The Hacker News · 9/2/2026

Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

CVE-2026-9586 (CVSS 9.3) is unauthenticated SQL injection in Sangoma Switchvox SMB Edition enabling remote code execution without credentials.

Read original coverage