Threat actors have been exploiting a critical-severity vulnerability in the enterprise VoIP telephony management solution Sangoma Switchvox, Horizon3 and CISA warn.
Tracked as CVE-2026-9586 (CVSS score of 9.3) and described as an unauthenticated SQL injection issue, the security defect can be exploited remotely for arbitrary code execution.
It resides in an endpoint that processes XML content, which did not perform sanitization or parameterization when concatenating the user-controlled PhoneIP value into PostgreSQL queries.
“An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution,” a NIST advisory reads.
On Tuesday, cybersecurity firm Horizon3 warned that threat actors had started exploiting CVE-2026-9586 in the wild and shared indicators of compromise (IoCs) to help organizations identify potential intrusions.
On Wednesday, the US cybersecurity agency CISA added the security flaw to its Known Exploited Vulnerabilities (KEV) catalog along with six other issues, including the JFrog Artifactory bug and two SonicWall SMA1000 zero-days recently flagged as exploited.
The fifth vulnerability added to CISA KEV is CVE-2026-48710, an HTTP request/response smuggling flaw in the lightweight ASGI framework Starlette that was publicly disclosed in May. Hackers have been exploiting it since May, Horizon3 said in early June.
Next in line is CVE-2026-49869, a critical-severity command injection defect in the open source orchestration platform Kestra that was disclosed in June and flagged as exploited by Microsoft last week.
The last vulnerability added to CISA’s KEV list on Wednesday is CVE-2026-59822, a high-severity authentication bypass in LiteLLM. Last week, Wiz said its honeypots caught exploit attempts targeting this bug.
CISA is urging federal agencies to patch these vulnerabilities within three days, except for the Kestra and Starlette flaws, which should be patched within two weeks, in line with BOD 26-04’s recommendations.
Related: Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability
Related: Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities
Related: Exploit Published for Fresh Cleo Harmony Vulnerability
Related: Hackers Start Exploiting Critical Langflow Vulnerability


