Wire · opportunities
Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 2 September 2026 · Fusion42 review
Attackers are exploiting a critical unauthenticated SQL injection vulnerability (CVE-2026-9586) in Sangoma Switchvox SMB Edition 8.3, enabling remote code execution without credentials. The flaw affects about 4,000 internet-exposed instances, mostly in the U.S., with active exploitation starting August 30, 2026.
This Wire brief sits within Fusion42's coverage of Cybersecurity.
◆ ◆ The Wire takeaway
VoIP platform security just took a hit that exposes thousands of U.S.-based systems to remote takeover without needing credentials. You must prioritise emergency patching or risk being the next target in voice communications security.
◆ Coverage
1 source · 2 Sep 2026
◆ Related on Wire
◆ Topics