Follow

Sangoma Switchvox flaw hit in active RCE exploitation Attackers are exploiting CVE-2026-9586, an unauthenticated SQL injection in Sangoma Switchvox that enables remote code execution via the /pa endpoint. Horizon3 observed rapid attacks from 176.65.148.184 on August 30, including reverse shell deployment, process enumeration, and base64-encoded data exfiltration. Sangoma patched the issue in Switchvox 8.4.0.2 on July 14.

http://176.65.148.184/

· · lailagislason · 0 · 0 · 1
Sign in to participate in the conversation
Mastodon

The social network of the future: No ads, no corporate surveillance, ethical design, and decentralization! Own your data with Mastodon!