Switchvox CVE-2026-9586 enters KEV: unauthenticated SQL injection can reach RCE
Published 10 Sep 2026 · Severity: critical
CISA added Sangoma Switchvox CVE-2026-9586 to KEV on 2 September 2026. The flaw allows an unauthenticated remote attacker to inject SQL against the PostgreSQL backend, with database operations and remote code execution possible. Confirm affected appliances, apply Sangoma’s fixed release and conduct the forensic triage appropriate to an exploited internet-reachable communications system.