HackerFeeds

CyberSecurity News

Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

The Hacker News
· September 2, 2026

AI summary

Threat actors are taking advantage of a critical security flaw in the Sangoma Switchvox enterprise VoIP platform to deploy reverse shells without needing credentials. The vulnerability, identified as CVE-2026-9586, has a CVSS score of 9.3 and is a severe unauthenticated SQL injection issue. It affects Sangoma Switchvox SMB Edition 8.3 and allows attackers to execute arbitrary code remotely. This enables remote code execution without authentication, posing a significant risk. The vulnerability is specifically found in version 8.3, build 104997, of the Switchvox SMB Edition. Attackers can exploit this flaw to gain unauthorized access and execute malicious code.

Vulnerabilities mentioned

Read the full article at The Hacker Newsthehackernews.com/2026/09/attackers-exploit-critical-switchvox.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.