Hackers have been exploiting a critical-severity vulnerability (CVE-2026-9586) in the enterprise VoIP telephony management solution Sangoma Switchvox.

Attackers exploit a patched Switchvox SQL injection flaw to deploy reverse shells, with about 4,000 instances exposed online.

Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution.