Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: High
Victim: Organizations using Sangoma Switchvox SMB Edition 8.3
Incident: Active exploitation of CVE-2026-9586 to achieve unauthenticated remote code execution.
Impact: Full server compromise, database exfiltration, and the ability to forge authentication materials.
Attacker: Unidentified threat actors
Analysis: CVE-2026-9586 allows unauthenticated attackers to execute arbitrary code as a PostgreSQL superuser via a flaw in the /pa endpoint. Threat actors are currently targeting internet-exposed instances to exfiltrate signing keys and establish persistent access. The vulnerability is particularly dangerous as it requires no credentials to achieve full system compromise.
Recommendations: Update Sangoma Switchvox to version 8.4.0.2 or higher immediately.; Restrict public internet access to VoIP management interfaces and the /pa endpoint.; Audit /var/log/switchvox/db-quirks.log for evidence of SQL injection attempts.
Source: The Hacker News
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source