Act
active
Active exploitation of Sangoma Switchvox SQLi flaw deploys reverse shells
- Engineer — Act: CISA KEV-listed, public PoC on GitHub, and confirmed active exploitation: if you run Sangoma Switchvox, patch CVE-2026-9586 immediately or isolate the admin interface from untrusted networks until a patch is applied.
- SOC/IR — Act: Attackers are landing reverse shells via unauthenticated exploitation on edge VoIP devices; hunt for anomalous outbound connections originating from Switchvox hosts and sweep for post-exploitation activity (new processes, lateral movement) since the vulnerability became public.
- Leader — Plan: Confirm with engineering whether Switchvox is in the environment; if so, verify patching is prioritized this week given CISA KEV status — not yet a board-level event, but the KEV listing warrants a same-week check-in.
- Signals: CVE-2026-9586 — CISA KEV: listed, EPSS 0.12, public PoC on GitHub, reported by 2 collected sources
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.