๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability
Summary
Sangoma Switchvox contains a SQL injection vulnerability (a flaw that lets attackers insert malicious database commands into input fields) that allows unauthenticated attackers to run arbitrary SQL statements and potentially execute remote code against the backend PostgreSQL database (the system storing the application's data). This vulnerability is actively being exploited by real attackers.
Solution / Mitigation
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA's BOD 26-04 guidance. Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. See Sangoma Switchvox Release Notes Version 8.4.0.2 (July 14, 2026) for vendor-specific patching instructions.
Vulnerability Details
EPSS: 1.1%
Yes
๐ฅ Actively Exploited
September 1, 2026
Classification
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-9586
First tracked: September 2, 2026 at 02:00 PM
Classified by LLM (prompt v3) ยท confidence: 95%