02 September 2026
Reference: CVE-2026-9586
1. What is being reported?
The vulnerability is a type of attack called SQL injection in the Switchvox phone system software. It happens because the system does not properly check certain information it receives, allowing attackers to run harmful commands on the system remotely without logging in.
2. What this means in plain English
If your organisation uses this version of Switchvox, attackers could potentially access sensitive data or even take over your phone system. This could disrupt your business calls or expose private information.
3. Could this affect a small business?
Small businesses or charities using Sangoma Switchvox SMB Edition 8.3 could be at risk. Organisations not using this software or using a different version are likely not affected.
4. What to do now
- Check if your organisation uses Sangoma Switchvox SMB Edition 8.3.
- Contact your IT provider or software supplier immediately to ask about patches or updates that fix this issue.
- If you cannot update quickly, consider restricting external access to the phone system until a fix is applied.
- Monitor your phone system for any unusual activity or signs of compromise.
5. Ask your IT provider
Does our current version of Sangoma Switchvox SMB Edition include the CVE-2026-9586 vulnerability, and what steps are being taken to protect us?
6. Bottom line
If you use this phone system software, act quickly to check and update it to avoid serious security risks.
Information based on CISA KEV, NVD and reputable security reporting.