Hackers Exploit Critical VoIP Vulnerability to Seize Control of U.S. Systems
AI-generated from multiple sources. Verify before acting on this reporting.
SEPT. 2, 2026 — Cyberattackers are actively exploiting a critical security flaw in the Sangoma Switchvox Voice over Internet Protocol (VoIP) platform to gain unauthorized access to systems across the United States. The vulnerability, identified as CVE-2026-9586, allows malicious actors to inject SQL commands without requiring authentication, enabling them to deploy reverse shells and execute remote code on affected devices.
Security researchers from Horizon3 confirmed the active exploitation of the flaw late Tuesday evening. The group reported that attackers are leveraging the unauthenticated SQL injection vulnerability to bypass standard security controls. Once inside a vulnerable system, the intruders can install reverse shells, which create backdoor connections allowing them to run arbitrary operating-system commands. This level of access grants attackers full control over the compromised infrastructure.
The attack campaign is primarily targeting devices located within the United States. Sangoma Switchvox is widely used by businesses and organizations for managing telephone systems and unified communications. The widespread deployment of the platform means a significant number of potential targets are exposed to this specific threat vector. The nature of the vulnerability allows attackers to strike from anywhere, provided they can identify an unpatched instance of the software.
Horizon3 researchers detailed the technical mechanics of the breach, noting that the lack of authentication requirements makes the exploit particularly dangerous. Unlike attacks that require stolen credentials or complex social engineering, this method relies solely on the existence of the software bug. Attackers can scan for vulnerable IP addresses and immediately attempt to inject malicious code. Successful exploitation results in the installation of a reverse shell, effectively handing over the keys to the system's operating environment.
The immediate impact includes the potential for data theft, service disruption, and the use of compromised VoIP systems as launchpads for further attacks. Organizations relying on Sangoma Switchvox are urged to assess their exposure immediately. While the specific group behind the attacks remains unidentified, the coordinated nature of the exploitation suggests a targeted effort rather than opportunistic scanning.
As of Tuesday night, no official patch has been announced by Sangoma to address CVE-2026-9586. The timeline for a fix remains unclear, leaving administrators in a difficult position as they attempt to mitigate the risk while maintaining essential communication services. Security experts are monitoring the situation closely, tracking whether the scope of the attacks expands beyond the initial targets in the United States.
Questions remain regarding the full extent of the compromise and whether any specific organizations have already been breached. The speed at which attackers are moving suggests that the window for prevention is narrowing rapidly. Until a definitive solution is deployed, vulnerable systems remain open to remote takeover.