← Back

Wire · opportunities

Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

Published

2 September 2026

Topic

opportunities

Sectors

Cybersecurity

Geography

United States

Source

Read at thehackernews.com

Verified

Fusion42 · 2 September 2026 · Fusion42 review

Attackers are exploiting a critical unauthenticated SQL injection vulnerability (CVE-2026-9586) in Sangoma Switchvox SMB Edition 8.3, enabling remote code execution without credentials. The flaw affects about 4,000 internet-exposed instances, mostly in the U.S., with active exploitation starting August 30, 2026.

This Wire brief sits within Fusion42's coverage of Cybersecurity.

◆ The Wire takeaway

VoIP platform security just took a hit that exposes thousands of U.S.-based systems to remote takeover without needing credentials. You must prioritise emergency patching or risk being the next target in voice communications security.

Coverage

1 source · 2 Sep 2026

Related on Wire

Topics

Cybersecurityswitchvoxsql-injectionrcevoipcybersecuritysangoma