Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com
← Back to Vulnerability Briefs

Critical Security Flaw Found in Sangoma Switchvox Phone System

A serious security weakness has been found in Sangoma Switchvox SMB Edition 8.3 that could allow attackers to take control of your phone system without needing a password. This could lead to data theft or disruption of your communications.

02 September 2026

Reference: CVE-2026-9586

1. What is being reported?

The vulnerability is a type of attack called SQL injection in the Switchvox phone system software. It happens because the system does not properly check certain information it receives, allowing attackers to run harmful commands on the system remotely without logging in.

2. What this means in plain English

If your organisation uses this version of Switchvox, attackers could potentially access sensitive data or even take over your phone system. This could disrupt your business calls or expose private information.

3. Could this affect a small business?

Small businesses or charities using Sangoma Switchvox SMB Edition 8.3 could be at risk. Organisations not using this software or using a different version are likely not affected.

4. What to do now

  • Check if your organisation uses Sangoma Switchvox SMB Edition 8.3.
  • Contact your IT provider or software supplier immediately to ask about patches or updates that fix this issue.
  • If you cannot update quickly, consider restricting external access to the phone system until a fix is applied.
  • Monitor your phone system for any unusual activity or signs of compromise.

5. Ask your IT provider

Does our current version of Sangoma Switchvox SMB Edition include the CVE-2026-9586 vulnerability, and what steps are being taken to protect us?

6. Bottom line

If you use this phone system software, act quickly to check and update it to avoid serious security risks.

Information based on CISA KEV, NVD and reputable security reporting.

Back to Vulnerability Briefs