CISA added CVE-2026-9586, a critical, unauthenticated SQL injection in Sangoma Switchvox, to the Known Exploited Vulnerabilities catalog on 2026-09-02, with a remediation due date of 2026-09-05.
What Is It
CVE-2026-9586 is an unauthenticated SQL injection (CWE-89) in Sangoma Switchvox SMB Edition. The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. A remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database, reportedly via a single crafted request; with impact that may extend from database operations to remote code execution, per Horizon3.ai's public disclosure.
It carries a CVSS 3.1 base score of 9.8 (CRITICAL, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and a CVSS 4.0 score of 9.3 (CRITICAL).
Why It Matters
CISA's KEV listing confirms active exploitation. The accompanying SSVC decision points rate exploitation as active, automatable as yes, and technical impact as total: meaning attacks can be scripted at scale and yield full control of the affected system.
No authentication, no user interaction, and low attack complexity mean the bar for exploitation can be as low as a single network request. The KEV entry also flags forensic triage as required, and ransomware campaign use is currently listed as Unknown.
What's Vulnerable
- Vendor/product: Sangoma Switchvox (SMB Edition), on-premises
- Affected versions: 8.2.2.1 up to (but not including) 8.4.0.2
- Specifically cited in the NVD record: Switchvox SMB Edition 8.3 (104997)
Patch Status
Fixed in Switchvox 8.4.0.2, released 2026-07-14 per Sangoma's release notes.
CISA's required action: apply mitigations per vendor instructions in compliance with BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's Forensics Triage Requirements. Follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and adhering to BOD 26-04 patching guidelines. Due date: 2026-09-05.
Sources
- NVD, CVE-2026-9586: https://nvd.nist.gov/vuln/detail/CVE-2026-9586
- CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-9586
- Sangoma; Switchvox Release Notes 8.4.0.2 (July 14, 2026): https://sangomakb.atlassian.net/wiki/spaces/Switchvox/pages/1802371073/Switchvox+-+Release+Notes+Version+8.4.0.2+July+14+2026
- SRA Labs; Switchvox research: https://labs.sra.io/posts/switchvox/
- Horizon3.ai; CVE-2026-9586 Sangoma Switchvox RCE disclosure: https://horizon3.ai/attack-research/disclosures/cve-2026-9586-sangoma-switchvox-rce/
- CISA BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- CISA BOD 26-04 Implementation Guidance (Forensics Triage Requirements): https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk