Back to all news
Security

Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

The Hacker News·September 2, 2026·1 min read
Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

Threat actors are exploiting a severe vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that allows unauthenticated remote code execution. The flaw, CVE-2026-9586 with a CVSS score of 9.3, is a critical unauthenticated SQL injection vulnerability in Switchvox SMB Edition 8.3 that enables arbitrary code execution.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store