Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Unleashing the Lurker: How Switchvox's Critical Flaw Unleashes a Can of Worms for Attackers



A critical flaw in Sangoma Switchvox has been exposed, allowing attackers to deploy reverse shells without credentials. Learn how this vulnerability is being exploited and the measures being taken to mitigate its impact.

  • There is a critical flaw in Sangoma Switchvox, an enterprise VoIP platform, allowing attackers to deploy reverse shells without credentials.
  • The vulnerability, CVE-2026-9586, has a CVSS score of 9.3, categorizing it as a high-severity unauthenticated SQL injection vulnerability.
  • Attackers can remotely execute arbitrary code as the PostgreSQL superuser without requiring any credentials.
  • Patches were released by Sangoma for Switchvox 8.4.0.2, but the window of opportunity for exploitation is still open.
  • The vulnerability was independently discovered and reported by Security Risk Advisors (SRA) Labs in May.
  • Exploitation efforts involve deploying reverse shells and running Base64-encoded commands to enumerate running processes.
  • The discovery highlights the importance of regular vulnerability assessments and staying vigilant in the face of emerging threats.



  • The world of cybersecurity is ever-evolving, with new threats and vulnerabilities emerging on a daily basis. Recently, a critical flaw in Sangoma Switchvox, an enterprise VoIP platform, has been exposed, allowing attackers to deploy reverse shells without credentials. This vulnerability, designated as CVE-2026-9586, boasts a CVSS score of 9.3, categorizing it as a high-severity unauthenticated SQL injection vulnerability.

    The vulnerability, which affects Sangoma Switchvox SMB Edition 8.3 (104997), allows attackers to remotely execute arbitrary code as the PostgreSQL superuser without requiring any credentials. This is a critical concern, as it enables attackers to manipulate the system without the need for authentication, thereby expanding the attack surface.

    Sangoma released patches for the flaw in Switchvox 8.4.0.2 on July 14, 2026, a move that is expected to mitigate the risks associated with this vulnerability. However, the window of opportunity for attackers to exploit this flaw is still open, as many instances of Switchvox are exposed to the internet, with about 4,000 instances found in the U.S.

    The same vulnerability was independently discovered and reported by Security Risk Advisors (SRA) Labs in May. SRA Labs conducted a test of the vulnerability and found that an unauthenticated attacker could execute arbitrary SQL statements against the backend PostgreSQL database, including database operations and remote code execution. This capability allows attackers to exfiltrate sensitive data, such as the cookie signing key, and execute arbitrary code on the server, thereby invoking a reverse shell on the target machine.

    The exploitation efforts targeting the honeypots involve the deployment of reverse shells on compromised systems, followed by running Base64-encoded commands to enumerate running processes. The autonomous penetration testing platform has shared indicators of compromise (IOCs) for this vulnerability, including the IP address 176.65.148[.]184, which has been flagged on VirusTotal for conducting port scanning, brute-force, and exploitation efforts.

    Security researcher Zach Hanley observed that the quick succession of exploit attempts across multiple honeypots from the same source IP indicates that it is likely that most internet-exposed Switchvox instances will be or have already been targeted. This highlights the critical nature of this vulnerability and the need for prompt action to patch and secure affected systems.

    The discovery of this vulnerability serves as a reminder of the importance of regular vulnerability assessments and the need for organizations to stay vigilant in the face of emerging threats. As the threat landscape continues to evolve, it is essential for organizations to prioritize their cybersecurity posture and invest in measures to prevent and respond to such incidents.

    In conclusion, the critical flaw in Sangoma Switchvox has unleashed a can of worms for attackers, allowing them to deploy reverse shells without credentials. The impact of this vulnerability cannot be overstated, as it expands the attack surface and enables attackers to manipulate the system without the need for authentication. The timely release of patches by Sangoma and the efforts of security researchers like Zach Hanley are crucial in mitigating the risks associated with this vulnerability.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Unleashing-the-Lurker-How-Switchvoxs-Critical-Flaw-Unleashes-a-Can-of-Worms-for-Attackers-ehn.shtml

  • https://thehackernews.com/2026/09/attackers-exploit-critical-switchvox.html

  • https://nvd.nist.gov/vuln/detail/CVE-2026-9586

  • https://www.cvedetails.com/cve/CVE-2026-9586/


  • Published: Wed Sep 2 03:40:31 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us