Exploit attempts against a critical Sangoma Switchvox vulnerability began August 30, roughly six weeks after the vendor shipped a patch, and researchers say most internet-exposed phone systems may already be in scope.
CVE-2026-9586 is an unauthenticated SQL injection in Switchvox SMB Edition 8.3. The /pa endpoint processes XML beginning with PolycomIPPhone and concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization, letting one crafted request execute arbitrary SQL or code as the database superuser. Sangoma fixed the flaw in Switchvox 8.4.0.2 on July 14.
Horizon3.ai, which reported the bug along with 11 other Switchvox issues in April, says valid exploitation attempts have hit its honeypots since August 30, with attackers deploying reverse shells and then running Base64-encoded commands to enumerate processes. Security Risk Advisors independently found the same flaw in May. Roughly 4,000 Switchvox instances are exposed to the internet, most of them in the United States.
Indicators include traces of the SQL injection payload in /var/log/switchvox/db-quirks.log on devices with SSH enabled, and scans from the address 176.65.148.184. Horizon3.ai researcher Zach Hanley warns the rapid succession of hits across honeypots suggests most exposed instances will be, or already have been, targeted.
