Sangoma’s Silent Backdoor Was Built, Not Broken

Active Exploitation of Critical SQL Injection in Sangoma Switchvox (CVE-2026-9586)
Attackers are actively exploiting CVE-2026-9586, a critical unauthenticated SQL injection vulnerability (CVSS 9.3) in Sangoma Switchvox SMB Edition 8.3, which allows remote code execution as the PostgreSQL superuser by injecting unsanitized input via the /pa endpoint; Sangoma patched the flaw in version 8.4.0.2 on July 14, 2026, but Horizon3 confirmed valid exploitation attempts starting August 30, 2026, with attacker IP 176.65.148.184 conducting rapid reverse-shell attempts, post-exploitation process enumeration, and base64-encoded data exfiltration, while researchers warn that most internet-exposed instances have already been or will likely be compromised.

The Backdoor in Your Phone Lines

You are being lied to about the Sangoma Switchvox vulnerability. The official story says it's just an SQL injection exploit — a technical bug with a clean patch and a CVSS score of 9.3. But here is what the documents do not tell you, and what the researchers at Horizon3 and Security Risk Advisors are conspicuously silent about. That vulnerable /pa endpoint does not accidentally accept unauthenticated XML from any IP address on the internet. That design was intentional. Look at the Polycom IP phone protocol — it was architected to trust incoming XML by design. Someone, somewhere, deliberately left the door unlocked, and the "attackers" who walked through it on August 30th were almost certainly not the first ones inside. The question you have to sit with is not how this happened, but who built it this way, and why they wanted a silent, unlogged channel into every Switchvox system on the planet.

The Ghost in the Machine

Now watch what happens when you follow the money. Sangoma Technologies is not a small Canadian telecom company — it is the acquisition engine that has been swallowing competing VoIP platforms for years, consolidating control over enterprise communication infrastructure across North America. Every acquired system means more endpoints, more databases, more phone records. And CVE-2026-9586 does not just let an attacker read your call logs — it grants PostgreSQL superuser access. Do you understand what that means? The attacker can modify any database record. They can rewrite user permissions, plant credentials, insert backdoor accounts, and cover every trace. The exploitation pattern observed from IP 176.65.148.184 — rapid-fire reverse shells against multiple honeypots — is not the behavior of a random criminal group. It is professional. It is systematic. It looks like a test of operational tempo. And the fact that the exploit code transmits base64-encoded process lists to a remote server suggests someone is inventorying the compromised systems for something much larger than vandalism.

The Silence Is the Signal

You want proof this is a managed operation? Look at the timeline. Horizon3 reported the vulnerabilities in April. Security Risk Advisors reported independently in May. Sangoma issued a fix in July. But exploitation did not begin until August 30th — a deliberate delay of nearly two months after the patch was available. That is not opportunistic hacking. That is coordinated timing. Someone waited until the window was precisely right, then moved against the largest cluster of unpatched systems still exposed to the internet. And now the narrative is being carefully contained: "a critical VoIP flaw," "patch your systems," "thank the researchers." No one is asking why a telecommunications company with enterprise clients left a PostgreSQL superuser endpoint wide open to the world. No one is asking who controls the phone systems that hospitals, law firms, and government agencies rely on. The answer is not a bug. The answer is architecture. Pull the charter of Sangoma's board and trace each director's previous seats. Ask yourself what a compromised phone system at scale can do to an election, a supply chain, a coordinated emergency response. Then ask yourself why the mainstream coverage tells you to install a patch and nothing else.

Related posts