DEV Community

BeyondMachines for BeyondMachines

Posted on Originally published at beyondmachines.net

Attackers Exploit Critical Sangoma Switchvox Flaw to Deploy Reverse Shells

Summary

Sangoma patched 12 vulnerabilities in Switchvox, including a critical unauthenticated SQL injection (CVE-2026-9586) that attackers are currently using to gain remote code execution and steal authentication keys.

Take Action:

If you run Sangoma Switchvox, first make sure it isn't reachable from the internet and can only be accessed from trusted networks, then update immediately to version 8.4.0.2. Anything on version 8.3 or earlier is being actively attacked. Because attackers have been stealing keys, tokens and user data, also check /var/log/switchvox/db-quirks.log for signs of SQL injection, block the IP 176.65.148.184, and reset passwords and signing keys if you find anything suspicious.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)