Summary
Sangoma patched 12 vulnerabilities in Switchvox, including a critical unauthenticated SQL injection (CVE-2026-9586) that attackers are currently using to gain remote code execution and steal authentication keys.
Take Action:
If you run Sangoma Switchvox, first make sure it isn't reachable from the internet and can only be accessed from trusted networks, then update immediately to version 8.4.0.2. Anything on version 8.3 or earlier is being actively attacked. Because attackers have been stealing keys, tokens and user data, also check /var/log/switchvox/db-quirks.log for signs of SQL injection, block the IP 176.65.148.184, and reset passwords and signing keys if you find anything suspicious.
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (0)