ZeroDayAlert

CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability

Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.

Sangoma Switchvox Added to KEV 2026-09-02 Federal due 2026-09-05 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

Sangoma Switchvox is affected by this vulnerability. The flaw permits unauthenticated remote attackers to inject SQL statements into the backend PostgreSQL database, potentially leading to arbitrary database operations and remote code execution. The record does not specify which versions of Switchvox are vulnerable, nor does it detail whether this affects cloud-hosted, on-premises, or both deployment models.

How to check whether this touches you

  • Inventory your telephony and communications infrastructure to establish whether you operate or depend on Sangoma Switchvox in any form.
  • Determine whether your Switchvox deployment is reachable from the internet or from an untrusted network; check firewall rules, DNS records, and any exposed management or API interfaces.
  • Obtain the exact running version of Switchvox from the administrative interface or system logs; version alone is a signal, not proof of exposure, because vendors sometimes backport security patches to older releases.
  • If you operate a cloud instance, verify whether it is internet-facing or restricted to private connectivity.
  • Document the date your installation was deployed or last updated, as this will inform your forensic search window if exposure is later confirmed.

What to do

  1. Contact Sangoma immediately to obtain their remediation guidance and any available patches or mitigations; do not wait for your Federal remediation due date to begin this process.
  2. If a patch is available, plan and schedule its application according to CISA BOD 26-04 timelines; if Switchvox is internet-facing, treat this as a critical priority.
  3. Whilst awaiting a patch, restrict network access to Switchvox to trusted internal networks only; disable or firewall off any internet-exposed interfaces (such as management portals or APIs) unless operationally essential.
  4. Enable comprehensive logging of all database queries, authentication attempts, and error messages from Switchvox and its PostgreSQL backend; retain these logs for the forensic window (see below).
  5. If mitigations are unavailable and you cannot patch within your risk tolerance, evaluate whether discontinuing use of the product is feasible under BOD 26-04 guidance.
  6. Escalate this to your incident response and security teams immediately if Switchvox is internet-accessible or if you cannot apply a patch within your organisation's critical remediation window.

If you find you were exposed

Exploitation of SQL injection flaws typically occurs before public disclosure, so you must search backwards in your logs from the vulnerability announcement date. Review database query logs, PostgreSQL audit logs (if enabled), and Switchvox application logs for signs of malformed SQL, unexpected database schema changes, or unusual remote code execution attempts. Log retention is your limiting factor; if your retention period is shorter than the time between deployment and disclosure, your ability to detect past exploitation will be constrained. If you identify suspicious activity, preserve those logs and engage your incident response team or a forensic specialist to establish the scope of compromise.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2026-9586 is being exploited. It cannot tell you whether Switchvox is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →