hacker-news · Crawled Sep 2, 2026

Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

1 IoCs
Read original article ↗

AI Summary

Threat actors are actively exploiting a critical unauthenticated SQL injection vulnerability, CVE-2026-9586, in Sangoma Switchvox SMB Edition 8.3 (104997), allowing remote code execution as the PostgreSQL superuser. The flaw exists in the /pa endpoint, which processes unsanitized XML input containing a user-controlled PhoneIP value, enabling arbitrary SQL execution. Attackers have been observed deploying reverse shells, executing Base64-encoded commands, and exfiltrating sensitive data such as cookie signing keys. Exploitation attempts have been detected in the wild since August 30, 2026, with one identified attacker IP involved in scanning, brute-forcing, and exploitation activities.

AI-extracted · verify before operational use

Indicators of Compromise 1 extracted

Type Value Detail
IP 176[.]65[.]148[.]184 Details →