
Hackers Exploit Critical Sangoma Switchvox SQL Injection Flaw for Unauthenticated RCE
Threat actors are actively attempting to exploit CVE-2026-9586, a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox that can be escalated to remote code execution. Researchers at Horizon3.ai said internet-facing honeypots run alongside Defused Cyber captured valid exploitation attempts on August 30, several weeks after Sangoma released security fixes for the enterprise VoIP platform. Sangoma […]
The post Hackers Exploit Critical Sangoma Switchvox SQL Injection Flaw for Unauthenticated RCE appeared first on Cyber Security News.