CyberHighSingle-sourceDeveloping
7.1
Critical SQLi in WordPress backup plugin enables unauthenticated site takeover
BleepingComputer·about 19 hours ago
Threat actors are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in Sangoma Switchvox VoIP systems, to achieve remote code execution and deploy reverse shells. The flaw enables full system compromise of affected PBX appliances, which are often internet-facing and trusted on internal networks. This active exploitation elevates the risk for organizations using Switchvox, and immediate patching is advised.