CISA Adds Switchvox Vulnerability to KEV Catalog
CISA added CVE-2026-9586 in Sangoma Switchvox SMB to the Known Exploited Vulnerabilities catalog. The unauthenticated SQL injection could lead to remote code execution; a fix has been available since July.

Switchvox vulnerability was added by CISA to the Known Exploited Vulnerabilities (KEV) catalog on September 2, 2026. It is CVE-2026-9586 in Sangoma Switchvox SMB. Inclusion in the catalog confirms that the flaw is being exploited in the wild. Operators of unpatched systems should prioritize deploying the available update and checking for possible signs of attack.
CVE-2026-9586 is an unauthenticated SQL injection in Switchvox SMB versions before 8.4.0.2. It does not require the attacker to log in and could lead to remote code execution on the affected server.
CISA Adds Switchvox Vulnerability to KEV
Inclusion in KEV follows findings by Horizon3. On August 30, it recorded valid attempts to exploit the flaw in its own honeypots. The observed activity included an attempt to create a reverse shell, followed by process enumeration on the system.
Honeypots are deliberately exposed decoy systems designed to monitor attack activity. Their records document exploitation attempts, but by themselves do not identify specific organizations that were attacked or the extent of successful compromises beyond this infrastructure.
CISA recommends following the vendor’s guidance. A fix is available in Switchvox version 8.4.0.2, released on July 14, 2026. Switchvox SMB systems running versions before this release are affected.
Updating and Checking Systems
Operators should verify their Switchvox version and update to 8.4.0.2 or a newer release. Because the vulnerability does not require authentication, internet-accessible installations warrant particular attention.
If exploitation is suspected, operators should review logs and communications with known attack infrastructure. However, checking alone may neither confirm nor rule out system compromise.
Horizon3 estimated approximately 4,000 publicly accessible devices. This figure was derived from its measurements and the Shodan service, so it may change. Specific victims, the attacker’s identity, and the extent of successful attacks have not been publicly confirmed.
No Confirmed Link to Ransomware
The addition of CVE-2026-9586 to KEV is an independent regulatory confirmation of active exploitation of the flaw. It does not, however, confirm a link to ransomware campaigns; no such connection is currently known.
Further information could come from a possible statement by Sangoma, additional indicators of compromise from security teams, or independent confirmation of victims and campaign attribution.
Sources
- CISA Known Exploited Vulnerabilities Catalog – Confirms the addition of CVE-2026-9586 to KEV on September 2, 2026, and the recommendation to follow the vendor’s guidance.
- Horizon3 – Off the Hook – Documents observations of valid exploits in honeypots, a reverse shell, log indicators, and a known IP address.
- Sangoma Switchvox Release Notes 8.4.0.2 – Confirms the release of Switchvox 8.4.0.2 on July 14, 2026, and security fixes including SQL injection.
- SRA Labs Advisory: Sangoma Switchvox SMB – Confirms the technical nature of CVE-2026-9586, affected versions, the critical CVSS 9.3 rating, and updating to 8.4.0.2 or later.
Verified and updated: 09/03/2026 06:21



