Cyber & AI intelligence
Wasteland.
Briefs indexed2377
Issues26
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-9586 2026-09-02

Sangoma Switchvox CVE-2026-9586: Unauthenticated SQL Injection Lands in CISA KEV

"CISA added CVE-2026-9586, a critical, unauthenticated SQL injection in Sangoma Switchvox, to the Known Exploited Vulnerabilities catalog on 2026-09-02, with a remediation due date of 2026-09-05."

CISA added CVE-2026-9586, a critical, unauthenticated SQL injection in Sangoma Switchvox, to the Known Exploited Vulnerabilities catalog on 2026-09-02, with a remediation due date of 2026-09-05.

What Is It

CVE-2026-9586 is an unauthenticated SQL injection (CWE-89) in Sangoma Switchvox SMB Edition. The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. A remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database, reportedly via a single crafted request; with impact that may extend from database operations to remote code execution, per Horizon3.ai's public disclosure.

It carries a CVSS 3.1 base score of 9.8 (CRITICAL, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and a CVSS 4.0 score of 9.3 (CRITICAL).

Why It Matters

CISA's KEV listing confirms active exploitation. The accompanying SSVC decision points rate exploitation as active, automatable as yes, and technical impact as total: meaning attacks can be scripted at scale and yield full control of the affected system.

No authentication, no user interaction, and low attack complexity mean the bar for exploitation can be as low as a single network request. The KEV entry also flags forensic triage as required, and ransomware campaign use is currently listed as Unknown.

What's Vulnerable

Patch Status

Fixed in Switchvox 8.4.0.2, released 2026-07-14 per Sangoma's release notes.

CISA's required action: apply mitigations per vendor instructions in compliance with BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's Forensics Triage Requirements. Follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and adhering to BOD 26-04 patching guidelines. Due date: 2026-09-05.

Sources