Sangoma Switchvox Phone Systems Under Active Attack — Patch Now
A serious security flaw in Sangoma Switchvox business phone systems is currently being exploited by attackers in real-world attacks, according to researchers. The vulnerability, tracked as CVE-2026-9586, is an unauthenticated SQL injection issue, meaning attackers don't need a username or password to exploit it. Once exploited, it can allow full remote code execution, giving attackers control over the affected system.
Switchvox is a phone system used by many small and medium businesses for voice communications and call management. Because the flaw doesn't require authentication, any exposed system reachable over the internet is at risk, and confirmed exploitation in the wild means attackers are actively scanning for and targeting vulnerable installations right now, not just theorising about it.
Businesses using Switchvox should treat this as an urgent priority. Vendors typically release patches or mitigation guidance once a vulnerability is confirmed to be exploited, and applying these updates quickly is the most effective way to reduce risk. Organisations should also review whether their phone systems are exposed directly to the internet and consider restricting access where possible.