Critical Flaw in Sangoma Switchvox VoIP Systems Being Actively Exploited
A critical vulnerability in Sangoma Switchvox, a popular enterprise VoIP phone system, is being actively exploited by attackers in the wild. Tracked as CVE-2026-9586 and rated 9.3 out of 10 in severity, the flaw is an unauthenticated SQL injection bug found in Switchvox SMB Edition 8.3. Because it requires no login credentials, attackers can exploit it remotely to run arbitrary code on vulnerable systems.
Once exploited, attackers have been observed deploying reverse shells - a technique that gives them ongoing remote control over the compromised device without needing to re-authenticate. This is particularly concerning for VoIP systems, which often sit at the intersection of a business's phone and IT network, meaning a breach could expose call data, customer information, or provide a foothold to move deeper into connected systems.
Organisations using Sangoma Switchvox, including managed service providers who deploy it for small business clients, should treat this as an urgent priority. Given the flaw allows unauthenticated remote code execution, any exposed Switchvox system reachable from the internet is at high risk until patched or otherwise mitigated.