CVE-2026-9586 | Sangoma Switchvox Unauthenticated SQL Injection Remote Code Execution Vulnerability
CVE-2026-9586 is a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition affecting versions prior to 8.4.0.2. The flaw exists in the /pa endpoint's PhoneAppsHandler.pm component, which concatenates user-controlled PhoneIP values directly into PostgreSQL queries without sanitization, allowing remote attackers to execute arbitrary SQL and achieve RCE. Horizon3 and Defused Cyber have observed active exploitation attempts in the wild since late August 2026.