CyberSecurity News
Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials
AI summary
Threat actors are taking advantage of a critical security flaw in the Sangoma Switchvox enterprise VoIP platform to deploy reverse shells without needing credentials. The vulnerability, identified as CVE-2026-9586, has a CVSS score of 9.3 and is a severe unauthenticated SQL injection issue. It affects Sangoma Switchvox SMB Edition 8.3 and allows attackers to execute arbitrary code remotely. This enables remote code execution without authentication, posing a significant risk. The vulnerability is specifically found in version 8.3, build 104997, of the Switchvox SMB Edition. Attackers can exploit this flaw to gain unauthorized access and execute malicious code.
Vulnerabilities mentioned
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

