What Happened
CISA added CVE-2026-9586 to its Known Exploited Vulnerabilities catalog on September 2, a CVSS 9.3 unauthenticated SQL injection flaw in Sangoma Switchvox SMB Edition, the enterprise VoIP platform used for business phone systems and call management. A single crafted request against the affected endpoint lets an attacker execute arbitrary SQL statements as the backend PostgreSQL superuser, a level of database access supporting both data theft and remote code execution on the underlying host. Sangoma shipped a fix in Switchvox 8.4.0.2 on July 14, 2026, roughly seven weeks before CISA confirmed active exploitation and added the flaw to its catalog. Federal agencies in the United States face a September 5 remediation deadline. Details are available from The Hacker News.
Why This Matters for Canadian Organizations
Switchvox runs as an on-premises or hosted phone system for small and mid-sized businesses, and Canadian organizations in this segment, including law firms, clinics, and municipal offices, favor VoIP platforms like Switchvox precisely because they avoid the overhead of enterprise telephony vendors. An unauthenticated path to database superuser access on a phone system exposes call detail records, voicemail contents, and administrative credentials stored inside the platform, information supporting further compromise of connected business systems. OSFI Guideline B-13 directs federally regulated financial institutions to maintain current vulnerability management practices across all IT assets, including edge systems like VoIP platforms falling outside typical patching cycles, and PIPEDA obligations extend to any personal information captured in call records or voicemail transcripts stored on a compromised system.
What to Do
Organizations running Sangoma Switchvox SMB Edition should confirm their deployment sits on version 8.4.0.2 or later immediately, treating this as an emergency patch rather than a scheduled maintenance item given confirmed active exploitation. Security teams unable to patch immediately should restrict administrative interface access to trusted internal networks and review PostgreSQL and application logs for signs of the SQL injection pattern CISA describes. Any organization confirming a compromise should rotate credentials stored on or reachable from the Switchvox host and assume database contents including call records reached the attacker. Full technical details are available from The Hacker News.






