LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Sep 2, 2026
CVSS 9.3 · Critical⚠ Actively exploited (CISA KEV)
9.3
CVSS score
Critical
Severity
Active
CISA KEV
No
Ransomware use
Sep 5, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-9586 to its Known Exploited Vulnerabilities catalog on Sep 2, 2026, with a federal patch deadline of Sep 5, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.

CVE-2026-9586 is a SQL injection weakness in Sangoma Switchvox. An unauthenticated remote attacker can send a single crafted request that runs arbitrary SQL against the product’s backend PostgreSQL database. That can mean unauthorized database reads or changes and, as described in the CISA summary, remote code execution. For IT and security teams, this matters because Switchvox is often reachable from the network or internet for voice and collaboration services; successful abuse can lead to full compromise of the appliance and anything it can reach.

Public detail beyond the CWE class and the CISA summary is limited here. Confirm exact affected builds, fixed releases, and deployment notes only against the vendor advisory and your own inventory.

How it works

This issue is classified as CWE-89 (SQL injection). In products of this class, user-controlled input is incorporated into database queries without adequate validation or parameterization. An attacker who can reach the vulnerable interface does not need valid credentials. They craft a request so that the application’s SQL statement is altered to run attacker-chosen commands against PostgreSQL.

According to the CISA summary, that includes arbitrary SQL operations on the backend database and remote code execution. Do not assume a particular URL, parameter, or payload: those mechanics are not provided in the facts above. Treat any internet- or WAN-facing Switchvox instance as high priority for verification until the vendor’s fixed version is confirmed installed.

Am I affected? How to find it in your systems

Sangoma Switchvox is a unified communications / PBX-style platform. It typically runs as a dedicated appliance or virtual appliance in data centers, branch offices, or cloud-hosted voice environments, often with web administration and telephony-related services exposed to administrators or users.

How to remediate

Patch first. Apply the vendor update or mitigation package named in the Sangoma advisory for CVE-2026-9586. Validate the install on a non-production instance if you have one, then roll out to production and confirm the running version matches the fixed release.

If you can't patch immediately

Compensating controls reduce—but do not eliminate—risk until the vendor fix is in place.

If your data may have been exposed

Actively exploited vulnerabilities of this severity can lead to full system compromise and data exposure from the appliance database and connected systems. Known ransomware use is not documented in the facts for this CVE; still treat confirmed exploitation as a potential breach. Perform forensic review of the host, related call detail and configuration data, and downstream integrations. As a quick personal check for credential stuffing risk after any incident, individuals can run a free exposure scan of their email addresses against known breach datasets while your team completes enterprise investigation and notification obligations.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSangoma · Switchvox
WeaknessCWE-89
CVSS base score9.3 (Critical)
CVSS vectorCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
PublishedJul 17, 2026
Added to CISA KEVSep 2, 2026
Federal patch deadlineSep 5, 2026
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities