Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    HPE Patches Critical RCE Vulnerabilities in AOS-CX

    September 5, 2026

    Anthropic’s Claude Can Now Autonomously Run Science Experiments With Lab Equipment

    September 5, 2026

    LinkedIn (2026) review | TechRadar

    September 5, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Sangoma Switchvox Vulnerabilities Exploited in the Wild
    Sangoma Switchvox Vulnerabilities Exploited in the Wild
    Cybersecurity

    Sangoma Switchvox Vulnerabilities Exploited in the Wild

    The Tech GuyBy The Tech GuySeptember 4, 2026No Comments2 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    Threat actors have been exploiting a critical-severity vulnerability in the enterprise VoIP telephony management solution Sangoma Switchvox, Horizon3 and CISA warn.

    Advertisement

    Tracked as CVE-2026-9586 (CVSS score of 9.3) and described as an unauthenticated SQL injection issue, the security defect can be exploited remotely for arbitrary code execution.

    It resides in an endpoint that processes XML content, which did not perform sanitization or parameterization when concatenating the user-controlled PhoneIP value into PostgreSQL queries.

    “An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution,” a NIST advisory reads.

    On Tuesday, cybersecurity firm Horizon3 warned that threat actors had started exploiting CVE-2026-9586 in the wild and shared indicators of compromise (IoCs) to help organizations identify potential intrusions.

    On Wednesday, the US cybersecurity agency CISA added the security flaw to its Known Exploited Vulnerabilities (KEV) catalog along with six other issues, including the JFrog Artifactory bug and two SonicWall SMA1000 zero-days recently flagged as exploited.

    Advertisement. Scroll to continue reading.

    The fifth vulnerability added to CISA KEV is CVE-2026-48710, an HTTP request/response smuggling flaw in the lightweight ASGI framework Starlette that was publicly disclosed in May. Hackers have been exploiting it since May, Horizon3 said in early June.

    Next in line is CVE-2026-49869, a critical-severity command injection defect in the open source orchestration platform Kestra that was disclosed in June and flagged as exploited by Microsoft last week.

    The last vulnerability added to CISA’s KEV list on Wednesday is CVE-2026-59822, a high-severity authentication bypass in LiteLLM. Last week, Wiz said its honeypots caught exploit attempts targeting this bug.

    CISA is urging federal agencies to patch these vulnerabilities within three days, except for the Kestra and Starlette flaws, which should be patched within two weeks, in line with BOD 26-04’s recommendations.

    Related: Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability

    Related: Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities

    Related: Exploit Published for Fresh Cleo Harmony Vulnerability

    Related: Hackers Start Exploiting Critical Langflow Vulnerability

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    HPE Patches Critical RCE Vulnerabilities in AOS-CX

    September 5, 2026

    In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation

    September 4, 2026

    AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million

    September 4, 2026

    Capsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue Agents

    September 4, 2026

    Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal

    September 3, 2026

    HiddenLayer Raises $100 Million for AI Runtime Security

    September 3, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026391 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026210 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202517 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    HPE Patches Critical RCE Vulnerabilities in AOS-CX

    September 5, 2026

    Anthropic’s Claude Can Now Autonomously Run Science Experiments With Lab Equipment

    September 5, 2026

    LinkedIn (2026) review | TechRadar

    September 5, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.