<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/hackers-exploit-sangoma-switchvox-flaw-to-deploy-reverse-shells-9mc2bz2no" -->

---
title: Hackers exploit Sangoma Switchvox flaw to deploy reverse...
description: Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection flaw in Sangoma Switchvox VoIP platform&#x27;s /pa HTTP endpoint that allows...
canonical: https://daily.dev/posts/hackers-exploit-sangoma-switchvox-flaw-to-deploy-reverse-shells-9mc2bz2no
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Hackers exploit Sangoma Switchvox flaw to deploy reverse shells | daily.dev
og:description: Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection flaw in Sangoma Switchvox VoIP platform&#x27;s /pa HTTP endpoint that allows...
og:url: https://daily.dev/posts/hackers-exploit-sangoma-switchvox-flaw-to-deploy-reverse-shells-9mc2bz2no
og:image: https://api.daily.dev/og/posts/9MC2bZ2nO.png
og:image:alt: Hackers exploit Sangoma Switchvox flaw to deploy reverse shells
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Hackers exploit Sangoma Switchvox flaw to deploy reverse shells

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 3 min read · 0 upvotes · 0 comments

## Summary

Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection flaw in Sangoma Switchvox VoIP platform's /pa HTTP endpoint that allows remote code execution via unparameterized SQL queries. Horizon3 researchers, who discovered and reported 12 flaws to Sangoma in April, observed real exploitation attempts on August 30 from a single IP attempting to establish reverse shells and exfiltrate process data. Sangoma patched the most severe flaw in version 8.4.0.2 released July 14. Roughly 4,000 internet-exposed Switchvox devices exist, mostly in the US, and administrators are urged to upgrade immediately and check logs for compromise indicators.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/hackers-exploit-sangoma-switchvox-flaw-to-deploy-reverse-shells>

## Questions this post answers

### What is CVE-2026-9586 and how does it affect Sangoma Switchvox?

CVE-2026-9586 is an unauthenticated SQL injection vulnerability in Sangoma Switchvox's /pa HTTP endpoint that can lead to remote code execution. The endpoint parses XML messages and directly concatenates the PhoneIP field into an unparameterized SQL query, letting attackers execute operating-system commands remotely, for example to establish reverse shells.

_Teams running VoIP infrastructure can track fast-moving vulnerability disclosures like this one on daily.dev._

### Which version of Switchvox fixes the actively exploited SQL injection vulnerability?

Sangoma fixed the vulnerability, along with 11 other flaws reported by Horizon3, in Switchvox version 8.4.0.2, released July 14. Administrators should upgrade to this version or later immediately, since attackers began actively exploiting the flaw on August 30 to deploy reverse shells.

_daily.dev helps admins stay current on patch releases before actively exploited flaws catch them off guard._

### How can I tell if my Sangoma Switchvox system has been compromised via CVE-2026-9586?

Check for suspicious statements in /var/log/switchvox/db-quirks.log and for network connections to the attacker's observed IP address, 176.65.148.184, particularly on port 39323. Horizon3's honeypots recorded rapid exploitation attempts from this single source IP collecting process information and exfiltrating it in base64-encoded form.

_Security engineers watching for indicators of compromise can follow incident details like these on daily.dev._

## Similar posts on daily.dev

- [CVE-2026-0826: How an Old Bug Can Feed AI-Powered Impersonation](https://daily.dev/posts/cve-2026-0826-how-an-old-bug-can-feed-ai-powered-impersonation-lqgyapfvo) · Rapid7 Cybersecurity Blog · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#sql](https://daily.dev/tags/sql)

[View this post on daily.dev](https://daily.dev/posts/hackers-exploit-sangoma-switchvox-flaw-to-deploy-reverse-shells-9mc2bz2no)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Hackers exploit Sangoma Switchvox flaw to deploy reverse shells","url":"https://daily.dev/posts/hackers-exploit-sangoma-switchvox-flaw-to-deploy-reverse-shells-9mc2bz2no","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/hackers-exploit-sangoma-switchvox-flaw-to-deploy-reverse-shells-9mc2bz2no"},"datePublished":"2026-09-03T05:31:40.085Z","dateModified":"2026-09-03T11:24:34.369Z","description":"Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection flaw in Sangoma Switchvox VoIP platform's /pa HTTP endpoint that allows...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/5535621c96977eb0e950ca1c6c4db177?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/5535621c96977eb0e950ca1c6c4db177?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/hackers-exploit-sangoma-switchvox-flaw-to-deploy-reverse-shells-9mc2bz2no","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,sql","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"Hackers exploit Sangoma Switchvox flaw to deploy reverse shells"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/hackers-exploit-sangoma-switchvox-flaw-to-deploy-reverse-shells-9mc2bz2no#faq","mainEntity":[{"@type":"Question","name":"What is CVE-2026-9586 and how does it affect Sangoma Switchvox?","acceptedAnswer":{"@type":"Answer","text":"CVE-2026-9586 is an unauthenticated SQL injection vulnerability in Sangoma Switchvox's /pa HTTP endpoint that can lead to remote code execution. The endpoint parses XML messages and directly concatenates the PhoneIP field into an unparameterized SQL query, letting attackers execute operating-system commands remotely, for example to establish reverse shells. Teams running VoIP infrastructure can track fast-moving vulnerability disclosures like this one on daily.dev."}},{"@type":"Question","name":"Which version of Switchvox fixes the actively exploited SQL injection vulnerability?","acceptedAnswer":{"@type":"Answer","text":"Sangoma fixed the vulnerability, along with 11 other flaws reported by Horizon3, in Switchvox version 8.4.0.2, released July 14. Administrators should upgrade to this version or later immediately, since attackers began actively exploiting the flaw on August 30 to deploy reverse shells. daily.dev helps admins stay current on patch releases before actively exploited flaws catch them off guard."}},{"@type":"Question","name":"How can I tell if my Sangoma Switchvox system has been compromised via CVE-2026-9586?","acceptedAnswer":{"@type":"Answer","text":"Check for suspicious statements in /var/log/switchvox/db-quirks.log and for network connections to the attacker's observed IP address, 176.65.148.184, particularly on port 39323. Horizon3's honeypots recorded rapid exploitation attempts from this single source IP collecting process information and exfiltrating it in base64-encoded form. Security engineers watching for indicators of compromise can follow incident details like these on daily.dev."}}]}
```

