Overview
- Honeypot telemetry showed active exploitation beginning Sunday, Aug. 30, with a single observed source IP dropping reverse shells and running encoded reconnaissance before exfiltrating data.
- The flaw, tracked as CVE-2026-9586 and rated CVSS 9.3, is an unauthenticated SQL injection in Switchvox’s /pa XML endpoint that concatenates the PhoneIP value into unparameterized PostgreSQL queries and can lead to remote code execution.
- Sangoma issued a patch on July 14 in Switchvox 8.4.0.2 that fixes the vulnerability and administrators are urged to upgrade immediately or isolate the management interface and /pa endpoint if they cannot patch.
- Indicators of compromise include suspicious entries in /var/log/switchvox/db-quirks.log and network connections to 176.65.148.184, notably on port 39323, and defenders should hunt for base64-encoded exfiltration and reverse-shell artifacts.
- About 4,000 Switchvox instances are exposed on the internet, mostly in the U.S., which raises the risk that small and mid-sized businesses could face stolen keys, forged authentication and persistent compromise if they remain unpatched.