Sangoma Switchvox flaw hit in active RCE exploitation Attackers are exploiting CVE-2026-9586, an unauthenticated SQL injection in Sangoma Switchvox that enables remote code execution via the /pa endpoint. Horizon3 observed rapid attacks from 176.65.148.184 on August 30, including reverse shell deployment, process enumeration, and base64-encoded data exfiltration. Sangoma patched the issue in Switchvox 8.4.0.2 on July 14.
http://176.65.148.184/