chiprook
← Security
SecuritySeptember 30, 2026, 09:00

CVE-2026-9586: SQL injection in Sangoma Switchvox rated 9.8

Sangoma Switchvox SMB Edition 8.3 contains CVE-2026-9586, a CVSS 9.8 SQL injection: an unauthenticated attacker can inject SQL through the PhoneIP XML field on the /pa provisioning endpoint, with remote code execution reachable from the same path. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2 September 2026; the fix shipped in version 8.4.0.2 in July.

CVE-2026-9586: SQL injection in Sangoma Switchvox rated 9.8
#Sangoma#Switchvox#CISA
Read next
Security

CVE-2026-75682 in Adobe Connect: SQL injection rated 9.9 leads to code execution

Security

CVE-2026-76461: SQL injection in Cisco email gateway grants root

Security

Metabase CVE-2026-72898: unauthenticated SQL injection exposes the data warehouse

Security

Roundcube SQL injection CVE-2026-48842 exploited in the wild