Sangoma Switchvox, an enterprise VoIP management platform, has suffered a critical SQL injection flaw, CVE-2026-9586, that allows remote code execution. The vulnerability has been actively exploited and is now listed in CISA’s Known Exploited Vulnerabilities catalog.
- CVE-2026-9586 is a 9.3 CVSS-rated unauthenticated SQL injection.
- Horizon3 and CISA have released indicators of compromise for this exploit.
- Federal agencies are urged to patch within three days.
The Sangoma Switchvox platform, used for enterprise VoIP telephony management, has been found to contain a severe SQL injection vulnerability identified as CVE-2026-9586. This flaw permits unauthenticated remote attackers to execute arbitrary SQL commands against the PostgreSQL backend, potentially leading to remote code execution.
The defect resides in an XML‑processing endpoint that fails to sanitize or parameterize the user‑controlled PhoneIP value before concatenating it into PostgreSQL queries. According to a NIST advisory, a single crafted request can perform database operations and trigger remote code execution.
On Tuesday, cybersecurity firm Horizon3 warned that threat actors were already exploiting CVE-2026-9586 in the wild and shared indicators of compromise to help organizations detect intrusions. The following day, U.S. agency CISA added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, underscoring its active threat status.
Alongside this, CISA has catalogued other critical issues such as Starlette’s HTTP smuggling flaw (CVE-2026-48710), Kestra’s command‑injection vulnerability (CVE-2026-49869), and LiteLLM’s authentication bypass (CVE-2026-59822). Federal agencies are urged to patch within three days, except for Kestra and Starlette, which have a two‑week window per BOD 26‑04 recommendations.
Why This Matters
BozokMedia analysis highlights that vulnerabilities in VoIP platforms can expose not only sensitive communication data but also compromise entire network infrastructures. Given Sangoma’s widespread adoption in large enterprises and government bodies, the risk scope is significant.
“Sangoma’s ubiquity means this flaw could precipitate a widespread data breach.”
Frequently Asked Questions
Q1: Are all versions of Sangoma Switchvox affected?
A1: Yes, the flaw exists across all releases that use XML processing. Patch version 6.4.2 is available.
Q2: How do I apply the patch?
A2: Download the latest firmware from Sangoma’s official site and follow the upgrade instructions provided.