Exploited Vulnerabilities Daily
🌐 繁體中文

← 所有新增項目

CVE-2026-9586: Sangoma Switchvox

Sangoma Switchvox 包含一個 SQL 注入弱點,它允許一個未經認證的遠端攻擊者對後端 PostgreSQL 資料庫執行任意的 SQL 語句,使用單一的編譯請求,包括資料庫操作和遠端程式碼執行。

CISA (English)

Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.

廠商
Sangoma
產品
Switchvox
漏洞
Sangoma Switchvox SQL Injection Vulnerability
加入日期
2026年9月2日
CISA 修補期限(美國聯邦機關)
2026年9月5日
已知用於勒索軟體攻擊
未知
弱點(CWE)
CWE-89

參考資料

本站僅為資訊目的整理 CISA 目錄,並非資安建議。請遵循廠商指引與官方公告。

最後更新: · 目錄版本 2026.10.02