CISA Adds Switchvox Vulnerability to KEV Catalog

CISA added CVE-2026-9586 in Sangoma Switchvox SMB to the Known Exploited Vulnerabilities catalog. The unauthenticated SQL injection could lead to remote code execution; a fix has been available since July.

Switchvox vulnerability was added by CISA to the Known Exploited Vulnerabilities (KEV) catalog on September 2, 2026. It is CVE-2026-9586 in Sangoma Switchvox SMB. Inclusion in the catalog confirms that the flaw is being exploited in the wild. Operators of unpatched systems should prioritize deploying the available update and checking for possible signs of attack.

CVE-2026-9586 is an unauthenticated SQL injection in Switchvox SMB versions before 8.4.0.2. It does not require the attacker to log in and could lead to remote code execution on the affected server.

CISA Adds Switchvox Vulnerability to KEV

Inclusion in KEV follows findings by Horizon3. On August 30, it recorded valid attempts to exploit the flaw in its own honeypots. The observed activity included an attempt to create a reverse shell, followed by process enumeration on the system.

Honeypots are deliberately exposed decoy systems designed to monitor attack activity. Their records document exploitation attempts, but by themselves do not identify specific organizations that were attacked or the extent of successful compromises beyond this infrastructure.

CISA recommends following the vendor’s guidance. A fix is available in Switchvox version 8.4.0.2, released on July 14, 2026. Switchvox SMB systems running versions before this release are affected.

Updating and Checking Systems

Operators should verify their Switchvox version and update to 8.4.0.2 or a newer release. Because the vulnerability does not require authentication, internet-accessible installations warrant particular attention.

If exploitation is suspected, operators should review logs and communications with known attack infrastructure. However, checking alone may neither confirm nor rule out system compromise.

Horizon3 estimated approximately 4,000 publicly accessible devices. This figure was derived from its measurements and the Shodan service, so it may change. Specific victims, the attacker’s identity, and the extent of successful attacks have not been publicly confirmed.

No Confirmed Link to Ransomware

The addition of CVE-2026-9586 to KEV is an independent regulatory confirmation of active exploitation of the flaw. It does not, however, confirm a link to ransomware campaigns; no such connection is currently known.

Further information could come from a possible statement by Sangoma, additional indicators of compromise from security teams, or independent confirmation of victims and campaign attribution.

Sources

Verified and updated: 09/03/2026 06:21

Sharing