NPM · SEPTEMBER 2026 · CONFIRMED

Critical Sangoma Switchvox SQL Injection Vulnerability Exploited

Severity
CRITICAL
Affected component
sangoma switchvox (npm)
Patched version
Not yet available
CVE-2026-9586

Sangoma Switchvox is affected by a critical SQL injection vulnerability, CVE-2026-9586, which allows remote code execution. Users of affected versions are at risk.

What happened

Sangoma Switchvox has a critical SQL injection vulnerability, CVE-2026-9586, that allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database. This can lead to remote code execution. The vulnerability exists in the /pa endpoint, which processes XML content and concatenates user-controlled values into PostgreSQL queries without proper sanitization. Horizon3.ai reported 12 distinct vulnerabilities in Switchvox to Sangoma in April 2026, of which CVE-2026-9586 is the most severe. Sangoma released patches in version 8.4.0.2 on July 14, 2026. Attackers are actively exploiting this flaw to deploy reverse shells.

The vulnerability was first flagged on September 2, 2026, and confirmed on the same day. It has a CVSS score of 9.3. There are approximately 4,000 instances of Switchvox exposed to the internet, primarily in the U.S. Users of versions prior to the patch are vulnerable.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If sangoma switchvox is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

If you are using Sangoma Switchvox and have not upgraded to version 8.4.0.2 or later, you are likely affected.

What should I do right now?

Upgrade to the latest version of Sangoma Switchvox and review your database access controls.

Has this been exploited in the wild?

Yes, CVE-2026-9586 is being actively exploited by attackers.

Sources

Join the 0Day waitlist →

← Back to all threats