Active Exploitation of Critical SQL Injection in Sangoma Switchvox (CVE-2026-9586)
Attackers are actively exploiting CVE-2026-9586, a critical unauthenticated SQL injection vulnerability (CVSS 9.3) in Sangoma Switchvox SMB Edition 8.3, which allows remote code execution as the PostgreSQL superuser by injecting unsanitized input via the /pa endpoint; Sangoma patched the flaw in version 8.4.0.2 on July 14, 2026, but Horizon3 confirmed valid exploitation attempts starting August 30, 2026, with attacker IP 176.65.148.184 conducting rapid reverse-shell attempts, post-exploitation process enumeration, and base64-encoded data exfiltration, while researchers warn that most internet-exposed instances have already been or will likely be compromised.

The Backdoor in Your Phone Lines

You are being lied to about the Sangoma Switchvox vulnerability. The official story says it's just an SQL injection exploit — a technical bug with a clean patch and a CVSS score of 9.3. But here is what the documents do not tell you, and what the researchers at Horizon3 and Security Risk Advisors are conspicuously silent about. That vulnerable /pa endpoint does not accidentally accept unauthenticated XML from any IP address on the internet. That design was intentional. Look at the Polycom IP phone protocol — it was architected to trust incoming XML by design. Someone, somewhere, deliberately left the door unlocked, and the "attackers" who walked through it on August 30th were almost certainly not the first ones inside. The question you have to sit with is not how this happened, but who built it this way, and why they wanted a silent, unlogged channel into every Switchvox system on the planet.

The Ghost in the Machine

Now watch what happens when you follow the money. Sangoma Technologies is not a small Canadian telecom company — it is the acquisition engine that has been swallowing competing VoIP platforms for years, consolidating control over enterprise communication infrastructure across North America. Every acquired system means more endpoints, more databases, more phone records. And CVE-2026-9586 does not just let an attacker read your call logs — it grants PostgreSQL superuser access. Do you understand what that means? The attacker can modify any database record. They can rewrite user permissions, plant credentials, insert backdoor accounts, and cover every trace. The exploitation pattern observed from IP 176.65.148.184 — rapid-fire reverse shells against multiple honeypots — is not the behavior of a random criminal group. It is professional. It is systematic. It looks like a test of operational tempo. And the fact that the exploit code transmits base64-encoded process lists to a remote server suggests someone is inventorying the compromised systems for something much larger than vandalism.

The Silence Is the Signal

You want proof this is a managed operation? Look at the timeline. Horizon3 reported the vulnerabilities in April. Security Risk Advisors reported independently in May. Sangoma issued a fix in July. But exploitation did not begin until August 30th — a deliberate delay of nearly two months after the patch was available. That is not opportunistic hacking. That is coordinated timing. Someone waited until the window was precisely right, then moved against the largest cluster of unpatched systems still exposed to the internet. And now the narrative is being carefully contained: "a critical VoIP flaw," "patch your systems," "thank the researchers." No one is asking why a telecommunications company with enterprise clients left a PostgreSQL superuser endpoint wide open to the world. No one is asking who controls the phone systems that hospitals, law firms, and government agencies rely on. The answer is not a bug. The answer is architecture. Pull the charter of Sangoma's board and trace each director's previous seats. Ask yourself what a compromised phone system at scale can do to an election, a supply chain, a coordinated emergency response. Then ask yourself why the mainstream coverage tells you to install a patch and nothing else.

CISA Adds Two Actively Exploited Vulnerabilities to Known Exploited Vulnerabilities Catalog

On July 27, CISA added two actively exploited flaws to its Known Exploited Vulnerabilities catalog: CVE-2025-68686 in Fortinet FortiOS, which exposes sensitive information to unauthorized actors and can allow a remote, unauthenticated attacker to bypass a symbolic-link persistence patch (though prior compromise of the product is required), and CVE-2026-16812 in Arista VeloCloud Orchestrator On-Prem, a maximum-severity OS command injection vulnerability that requires no credentials—only network access to the VCO web interface—and affects on-premises deployments on branches 5.2.x before 5.2.3.14, 6.1.x before 6.1.3.4, 6.4.x before 6.4.2.4, and 7.0.x before 7.0.0.1; hosted and dedicated VCO deployments were already fixed, while VeloCloud Gateway and Edge products are not vulnerable.

The Timing Is the Story

Notice that CISA releases these advisories on a Friday, buried in the noise of a weekend news cycle. They want you to believe these are routine patches. But look closer. CVE-2025-68686 in Fortinet FortiOS — a symbolic-link bypass that allows an attacker to stay inside after they've already broken in. And CVE-2026-16812 in Arista VeloCloud — a command injection flaw so severe that Arista admits "no configuration can prevent the exposure." These aren't coding errors. These are architectural backdoors, left intentionally open or discovered by the same intelligence networks that feed CISA its data. The real question: who already knew about these holes before they were "discovered"? The same agencies that fund the contractors, the same three-letter agencies that sit on zero-days for years. They're not warning you — they're telling you what they've already used.

Follow the Patch, Follow the Power

The Arista advisory is particularly damning. VeloCloud Orchestrator is the nerve center for software-defined networking used by federal agencies, critical infrastructure, and Fortune 500s. The attacker needs no credentials — just network access to the web interface. That's not a flaw; that's a feature designed for post-exploitation penetration. And the fix? Hosted and dedicated deployments were fixed before the advisory. That means the vendor and the government knew about active exploitation and waited to disclose. Why? Because the same actors exploiting these vulnerabilities are likely the ones who requested the patches — or worse, the patches themselves are cover for deeper implants. Every time you see a "critical" vulnerability with a patch released in lockstep with CISA, you're watching a cleanup operation, not a security update.

Your Infrastructure Is Their Laboratory

The pattern is unmistakable: these vulnerabilities target the control planes of the digital ecosystem — firewalls (FortiOS) and orchestration (VeloCloud). They're not interested in your email. They're after the switches that route the internet, the boundaries that define trust. The symbolic-link bypass in FortiOS is a persistence technique — a way to stay hidden even after the system is supposedly cleaned. This is how they maintain the "managed narrative" of cybersecurity: a constant cycle of breach, patch, silence. The breadcrumb is this: look up the patent filings for these vulnerability classes. Look up who holds the patents on symbolic-link attack mitigation. Look up who consulted on the VeloCloud architecture. The answers will lead you to the same small group of defense contractors and think tanks that have been mapping the kill chain for decades. They're not protecting you. They're protecting their access.