← All security news

Switchvox VoIP Flaw Under Active Attack

A phone-system server icon with a broken padlock over a database cylinder, an arrow leading to an open shell prompt, representing an unauthenticated SQL injection flaw in Sangoma Switchvox being exploited for remote code execution

Security researchers say attackers are actively exploiting a critical flaw in Sangoma Switchvox, a VoIP phone-system platform used by small and mid-sized businesses to run their office phones. The flaw, tracked as CVE-2026-9586 and scoring 9.3 out of 10 on the CVSS severity scale, lives in an endpoint that Switchvox uses to auto-configure desk phones. Because that endpoint builds a database query directly out of unchecked input, an attacker who can simply reach the server over the network — no username or password required — can inject their own SQL and run commands on the underlying system with full database-administrator privileges.

Sangoma was told about the flaw in April 2026 and shipped a fix in version 8.4.0.2 in July. But monitoring firm Horizon3.ai reports that real-world exploitation only began on 30 August: attackers scanning the internet for exposed Switchvox boxes, planting reverse shells to get a foothold, then dropping what looks like cryptomining malware as a follow-on payload. Roughly 4,000 Switchvox instances are reachable from the open internet today, most of them in the United States, and researchers expect that "most internet-exposed instances will be or have already been targeted."

What this means for your business

If your office phone system runs on Sangoma Switchvox, check the version today and update to 8.4.0.2 or later if you haven't already — this has been sitting as an available fix for over a month, and the attackers only needed to notice that. If you're not sure whether your provider manages this for you, that's worth a call this week rather than an assumption. More broadly, this is a reminder that phone systems, like any other server on your network, need the same patching discipline as your website or your accounting software: they're rarely built with public-internet exposure in mind, which is exactly why attackers scan for them specifically. If your Switchvox box has been directly reachable from the internet, it's worth having someone check server logs and running processes for anything unfamiliar, not just applying the patch and moving on.

Questions about your own setup? contact@techleetsolutions.com
Sources: BleepingComputer, The Hacker News, Help Net Security