Home ยท Wiki ยท Vulnerabilities & CVEs
type: vulnerability ยท created: 2026-09-03 ยท updated: 2026-09-03 ยท tags: ["cve", "vulnerability", "sql-injection", "sangoma", "switchvox"] ยท confidence: high ยท severity: high ยท affected_sectors: ["Technology", "Government", "Telecom"] ยท au_impact: true

CVE-2026-9586

Affected product: Sangoma Switchvox (SQL injection)

Patched version: Refer to vendor advisory

Active exploitation: Yes โ€” added to CISA KEV catalog on 2026-09-02

Assessment

CISA added this SQL injection in Sangoma Switchvox to its Known Exploited Vulnerabilities catalog, confirming active exploitation. Switchvox is a business phone system appliance, and the injection can allow attackers to query or tamper with the underlying database. Patching per vendor guidance is required, with federal agencies bound by binding operational directives.