Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Hackers exploit Sangoma Switchvox flaw to deploy reverse shells

    September 3, 2026

    Wyoming Adds Chainlink Proof of Reserve to FRNT Stablecoin

    September 3, 2026

    New Hubble images reveal a bizarre decagon over Saturn’s south pole

    September 3, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Hackers exploit Sangoma Switchvox flaw to deploy reverse shells
    • Wyoming Adds Chainlink Proof of Reserve to FRNT Stablecoin
    • New Hubble images reveal a bizarre decagon over Saturn’s south pole
    • Polluting Nylon Plants Clean Up Their Acts
    • Chart of the Week: Senior Republicans have given out the most money from leadership PACs • OpenSecrets
    • Don’t shy away from the language of loss | Death and dying
    • Did Trump divert first responders to DC beautification projects before Grand Canyon flash flood?
    • Australia news live: Marles says US relationship ‘transcends governments of the day’; Sydney to get new ferry stop | Australia news
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, September 3
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Hackers exploit Sangoma Switchvox flaw to deploy reverse shells

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 3, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution.

    According to security researchers at Horizon3, most of the internet-exposed Switchvox systems have either already been targeted or will be soon.

    Switchvox is an enterprise VoIP management platform used to configure and monitor business phone systems.

    CVE-2026-9586 is the most serious of 12 flaws Horizon3 discovered and reported to Sangoma on April 10. The vendor fixed them in Switchvox version 8.4.0.2, released on July 14.

    The vulnerability is an unauthenticated SQL injection problem in Sangoma Switchvox’s /pa HTTP endpoint. The researchers explain that the endpoint is exposed and parses an XML message containing specific key-value pairs.

    When /pa receives a request to notify another phone system, such as for an incoming or outgoing call event, it extracts the PhoneIP field from the XML message and directly concatenates its value into an unparameterized SQL query.

    The researchers demonstrated that this SQL injection can be exploited remotely to execute operating-system commands through a crafted XML request sent using the curl command.

    Exploit for CVE-2026-9586
    Exploit for CVE-2026-9586
    Source: Horizon3

    On August 30, Horizon3’s honeypots observed active exploitation on multiple systems in rapid succession from a single source IP address (176.65.148.184), with the attacker attempting to establish a reverse shell.

    In these attempts, the attacker executed an initial payload and then collected information about the top processes running on the Swithvox system. The data was then transmitted to a remote server in base64-encoded form.

    “Given the quick succession of exploit attempts across multiple honeypots from the same source IP, we believe that it is likely that most internet-exposed Switchvox instances will be or have already been targeted,” Horizon3 warns.

    “Currently Shodan shows that there are approximately 4,000 devices on the internet, with most located within the United States.”

    Horizon3 says it has not seen active exploitation of the remaining 11 flaws it discovered earlier.

    With CVE-2026-9586 being actively exploited, system administrators are recommended to upgrade to Switchvox version 8.4.0.2 or later as soon as possible, and check for signs of having been targeted in the meantime.

    Signs of compromise include suspicious statements in /var/log/switchvox/db-quirks.log and network connections to the observed attacker IP, particularly on port 39323.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    Deploy exploit Flaw hackers reverse Sangoma Shells Switchvox
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    OpenAI’s Astra Crosses ‘Critical’ Cyber Threshold After Finding Zero-Days

    Malicious Virtualizor Update Served via BGP Hijacking

    Exploit Published for Fresh Cleo Harmony Vulnerability

    Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs

    OpenLeash Adds a Human Check to Risky AI Agent Actions

    Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Hackers exploit Sangoma Switchvox flaw to deploy reverse shells

    September 3, 2026

    Wyoming Adds Chainlink Proof of Reserve to FRNT Stablecoin

    September 3, 2026

    New Hubble images reveal a bizarre decagon over Saturn’s south pole

    September 3, 2026

    Polluting Nylon Plants Clean Up Their Acts

    September 3, 2026
    Latest Posts

    Australia news live: Reformers member tells hearing he used factional funds to pay for bucks night; Taylor refuses to answer multiple Icac-related questions | Australia news

    July 31, 2026

    Trump administration to end Medicare Part D subsidy program. Will costs increase?

    July 31, 2026

    FP Live: Daniel Yergin on Why Energy Prices Didn’t Soar Higher This Year

    July 31, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Hackers exploit Sangoma Switchvox flaw to deploy reverse shells

    September 3, 2026

    Wyoming Adds Chainlink Proof of Reserve to FRNT Stablecoin

    September 3, 2026

    New Hubble images reveal a bizarre decagon over Saturn’s south pole

    September 3, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.