{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/sangoma/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:sangoma:switchvox:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-9586"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Switchvox (\u003c 8.4.0.2)"],"_cs_severities":["critical"],"_cs_tags":["webserver","sql-injection","vulnerability","cisa-kev"],"_cs_type":"advisory","_cs_vendors":["Sangoma"],"content_html":"\u003cp\u003eSangoma Switchvox versions prior to 8.4.0.2 are affected by a critical SQL injection vulnerability (CVE-2026-9586). This flaw enables an unauthenticated, remote attacker to interact with the backend PostgreSQL database by sending a single, specifically crafted HTTP request to the appliance. Successful exploitation grants the attacker the ability to execute arbitrary SQL statements. Depending on the database configuration and permissions, this capability may be leveraged to manipulate sensitive data or achieve remote code execution on the underlying appliance, which is typically used for telecommunications and VoIP services. Given the nature of these appliances, they are often internet-facing, increasing the risk of widespread automated scanning and exploitation. Organizations utilizing Switchvox must prioritize upgrading to version 8.4.0.2 or later in accordance with CISA Binding Operational Directive 26-04.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthenticated attackers to gain unauthorized access to the backend database of affected Sangoma Switchvox appliances. This can result in the full compromise of the device, data exfiltration, service disruption, or the potential for lateral movement within the network where the appliance is deployed. As a critical vulnerability listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, it poses an immediate risk to any enterprise-grade deployment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately upgrade all Sangoma Switchvox instances to version 8.4.0.2 or later to remediate CVE-2026-9586.\u003c/li\u003e\n\u003cli\u003eEvaluate the internet exposure of all Switchvox appliances and apply access control lists (ACLs) to restrict access to management interfaces to trusted IP addresses only.\u003c/li\u003e\n\u003cli\u003eAdhere to CISA BOD 26-04 guidelines for prioritizing security updates and perform forensics triage on any appliances that show signs of unauthorized access or anomalous activity.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-02T17:56:24Z","date_published":"2026-09-02T17:56:24Z","id":"https://feed.craftedsignal.io/briefs/2026-09-sangoma-switchvox-sqli/","summary":"Sangoma Switchvox is vulnerable to an unauthenticated SQL injection flaw that allows remote attackers to execute arbitrary SQL commands on the backend PostgreSQL database, potentially leading to remote code execution.","title":"SQL Injection Vulnerability in Sangoma Switchvox","url":"https://feed.craftedsignal.io/briefs/2026-09-sangoma-switchvox-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - Sangoma","version":"https://jsonfeed.org/version/1.1"}