CVE-2026-9586: Sangoma Switchvox
Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.
- Vendor
- Sangoma
- Product
- Switchvox
- Vulnerability
- Sangoma Switchvox SQL Injection Vulnerability
- Date added
- Sep 2, 2026
- CISA due date (U.S. federal agencies)
- Sep 5, 2026
- Known ransomware campaign use
- Unknown
- Weakness (CWE)
- CWE-89
References
This site summarizes CISA's catalog for information only. It is not security advice — follow your vendor's guidance and official advisories.
Last updated: · Catalog version 2026.10.02