9.3 CVSS Switchvox Flaw Actively Exploited for Reverse Shells
Sangoma Switchvox CVE-2026-9586, a 9.3 CVSS unauthenticated SQL injection flaw, has moved from patch advisory to active incident. Horizon3 honeypots caught reverse-shell attempts and process data exfiltration, and CISA KEV now tracks the bug. Security teams must patch to 8.4.0.2 or assume compromise on exposed VoIP systems.
Source: SecurityWeek · BleepingComputer