Switchvox CVE-2026-9586 enters KEV: unauthenticated SQL injection can reach RCE

Published 10 Sep 2026 · Severity: critical

CISA added Sangoma Switchvox CVE-2026-9586 to KEV on 2 September 2026. The flaw allows an unauthenticated remote attacker to inject SQL against the PostgreSQL backend, with database operations and remote code execution possible. Confirm affected appliances, apply Sangoma’s fixed release and conduct the forensic triage appropriate to an exploited internet-reachable communications system.