CuraSec

Act active

Active exploitation of Sangoma Switchvox SQLi flaw deploys reverse shells

2026-09-03 14:58 UTC · BleepingComputer · read the source ↗ #cve#voip#active-exploitation
  • Engineer — Act: CISA KEV-listed, public PoC on GitHub, and confirmed active exploitation: if you run Sangoma Switchvox, patch CVE-2026-9586 immediately or isolate the admin interface from untrusted networks until a patch is applied.
  • SOC/IR — Act: Attackers are landing reverse shells via unauthenticated exploitation on edge VoIP devices; hunt for anomalous outbound connections originating from Switchvox hosts and sweep for post-exploitation activity (new processes, lateral movement) since the vulnerability became public.
  • Leader — Plan: Confirm with engineering whether Switchvox is in the environment; if so, verify patching is prioritized this week given CISA KEV status — not yet a board-level event, but the KEV listing warrants a same-week check-in.
  • Signals: CVE-2026-9586 — CISA KEV: listed, EPSS 0.12, public PoC on GitHub, reported by 2 collected sources
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.