Affected Systems

Sangoma Switchvox VoIP platform versions prior to 8.4.0.2. Approximately 4,000 internet-exposed instances globally, primarily in the United States. Vulnerability CVE-2026-9586 affects the unauthenticated /pa HTTP endpoint.

Exploitation Status

Active exploitation confirmed. Horizon3 honeypots observed coordinated attacks on August 30, 2026 from IP 176.65.148.184 deploying reverse shells. Researchers assess most internet-exposed Switchvox systems have been or will be targeted. Public PoC available in Horizon3 disclosure.

Business Impact

Unauthenticated attackers can achieve remote code execution on enterprise VoIP systems, enabling full system compromise, call interception, credential theft, and lateral movement. Business phone systems may be disrupted or used for espionage. The vulnerability requires no authentication and is trivial to exploit via crafted XML requests to an exposed endpoint.

Urgency

🔴 Immediate

Recommended Actions

  • Upgrade all Sangoma Switchvox instances to version 8.4.0.2 or later immediately
  • Review /var/log/switchvox/db-quirks.log for suspicious SQL statements indicating exploitation attempts
  • Check firewall and IDS logs for connections to 176.65.148.184, especially on port 39323
  • Audit network connections from Switchvox systems for unexpected outbound traffic or reverse shell indicators
  • If patching cannot be completed within 24 hours, isolate Switchvox systems from internet exposure via firewall rules or place behind VPN