{"id":2660,"date":"2026-09-02T18:57:27","date_gmt":"2026-09-02T18:57:27","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2660"},"modified":"2026-09-02T18:57:27","modified_gmt":"2026-09-02T18:57:27","slug":"attackers-exploit-critical-switchvox-flaw-to-deploy-reverse-shells-without-credentials","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2660","title":{"rendered":"Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Sep 02, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Network Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgb9lLZ-CHEFECU3vn2ObupuzweLn7l23dnUcs2Qd1H5hsxut3nQKqe6W3lbh_cSyVF4PDgdfuSauhpeMKmW6wZGYW3kpVdhTfWhfpISTtfRzw25VOSvJNR8dnh_WWKwyZ0VnWe8nndwwfnWN-gPSdqmLBhJW2vkqjCkfMo8Eo-sucoSIr6JMT-7HxHnsCw\/s1700-nu-rw-lo-l85-e365\/admin.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution.<\/p>\n<p>The vulnerability in question is <strong><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-9586\" target=\"_blank\">CVE-2026-9586<\/a><\/strong> (CVSS score: 9.3), a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition 8.3 (104997) that can allow attackers to remotely execute arbitrary code as the PostgreSQL superuser without credentials. Sangoma <a href=\"https:\/\/sangomakb.atlassian.net\/wiki\/spaces\/Switchvox\/pages\/1802371073\/Switchvox+-+Release+Notes+Version+8.4.0.2+July+14+2026\" target=\"_blank\">released patches<\/a> for the flaw in Switchvox 8.4.0.2 on July 14, 2026.<\/p>\n<p>\u00abAn unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The \/pa endpoint processes XML content beginning with <polycomipphone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization,\u00bb according to a description of the flaw on CVE.org.<\/polycomipphone><\/p>\n<p>\u00abAn unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.\u00bb<\/p>\n<p>Horizon3.ai <a href=\"https:\/\/horizon3.ai\/attack-research\/disclosures\/cve-2026-9586-sangoma-switchvox-rce\/\" target=\"_blank\">said<\/a> CVE-2026-9586 is among the 12 distinct vulnerabilities in Switchvox that were reported to Sangoma in April 2026, and that it is now seeing valid exploitation attempts in the wild against the flaw starting August 30, 2026. There are about 4,000 instances exposed to the internet, most of them located in the U.S.<\/p>\n<p>The same vulnerability was independently <a href=\"https:\/\/labs.sra.io\/posts\/switchvox\/\" target=\"_blank\">discovered<\/a> and <a href=\"https:\/\/labs.sra.io\/posts\/switchvox-post\/\" target=\"_blank\">reported<\/a> by Security Risk Advisors (SRA) Labs in May.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/trust-world-update-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYq3TvePXpW0JIC7fXyv7A1W8KQqmb-AZqza2EuPyT0k8Nm5CwHYHISFLKXSKIAyR8JRtqEFQ4zx5jADiAkZKQ08nRWG1jCRV5YAbhKua7WaDdH1L6wsI-xOkoV4brlMfK44UwU-4Q1xqWg0uNN7sZkMCzci4RXYgWMNPHTtuKua7OR4oCbmxE10u0yKnR\/s728-nu-rw-lo-l85-e365\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abAs an unauthenticated attacker, we were able to perform arbitrary database operations, including extracting database contents, modifying user records, and escalating privileges to Switchvox web administrators,\u00bb SRA Labs said. \u00abWe also successfully executed arbitrary code on the server, invoking a reverse shell on the target machine.\u00bb<\/p>\n<p>In one example highlighted by SRA Labs, successful exploitation of CVE-2026-9586 makes it possible to exfiltrate the cookie signing key to an external server, thereby allowing an attacker to forge authentication material for arbitrary users.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjsvlQCARBSFZg44RPej08AO96ITLZTm3qVTf83qDjzHvC5k6IW-ryGokXzK-GJy79RbJhyphenhyphenhZ0QIvgAXi7wtC27jNJNWmYFW40blswEYOThiXO9DJVOVA9uA1YkJxjYZ879BIUKiW_Aa6AzaN65CS5I5YRmnC92HXL-wvNant6PJgPsapoCHcMHOEARqntw\/s1700-nu-rw-lo-l85-e365\/request.jpg\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjsvlQCARBSFZg44RPej08AO96ITLZTm3qVTf83qDjzHvC5k6IW-ryGokXzK-GJy79RbJhyphenhyphenhZ0QIvgAXi7wtC27jNJNWmYFW40blswEYOThiXO9DJVOVA9uA1YkJxjYZ879BIUKiW_Aa6AzaN65CS5I5YRmnC92HXL-wvNant6PJgPsapoCHcMHOEARqntw\/s1700-nu-rw-lo-l85-e365\/request.jpg\" alt=\"\" border=\"0\" data-original-height=\"340\" data-original-width=\"900\"\/><\/a><\/div>\n<p>The exploitation efforts targeting its honeypots involve the deployment of reverse shells on compromised systems, followed by running Base64-encoded commands to enumerate running processes. The autonomous penetration testing platform has shared the following indicators of compromise &#8211;<\/p>\n<ul>\n<li>On devices that have SSH access enabled, evidence of the SQL injection payload used can be observed in \u00ab\/var\/log\/switchvox\/db-quirks.log\u00bb<\/li>\n<li>Attacker IP address \u00ab<a href=\"https:\/\/www.virustotal.com\/gui\/ip-address\/176.65.148.184\/detection\" target=\"_blank\">176.65.148[.]184<\/a>\u00ab<\/li>\n<\/ul>\n<p>It&#8217;s worth noting that the IP address has been flagged on VirusTotal for conducting port scanning, brute-force, and exploitation efforts.<\/p>\n<p>\u00abGiven the quick succession of exploit attempts across multiple honeypots from the same source IP, we believe that it is likely that most internet exposed Switchvox instances will be or have already been targeted,\u00bb security researcher Zach Hanley said.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Sep 02, 2026Vulnerability \/ Network Security Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution. The&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2661,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[622,446,58,229,120,70,393,214,3274],"class_list":["post-2660","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-attackers","tag-credentials","tag-critical","tag-deploy","tag-exploit","tag-flaw","tag-reverse","tag-shells","tag-switchvox"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2660","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2660"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2660\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2661"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2660"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2660"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2660"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}