Attackers are exploiting a critical, newly addressed vulnerability in Sangoma Switchvox to compromise internet-exposed systems. Reports say CVE-2026-9586 is an unauthenticated SQL injection flaw that can be leveraged for remote code execution, including the deployment of reverse shells.

CVE-2026-9586 carries a high severity score (CVSS 9.3). Both outlets describe the issue as affecting Sangoma Switchvox SMB Edition 8.3 (104997). Help Net Security adds that active exploitation is underway against exposed instances and urges organizations to check immediately for indicators of compromise. The Hacker News focuses more on the technical impact and exploitation outcome, while Help Net Security emphasizes the current threat activity and practical response.

Overall, the accounts align on the nature of the vulnerability, its critical severity, the impacted product edition/version, and that exploitation is being observed in the wild against systems accessible from the internet.