-
Hackers are attacking a serious flaw in Sangoma Switchvox, a tool that businesses use to run their phone systems.
-
The bug lets attackers break in without a password and take control of the system.
-
Sangoma has released a fix, but thousands of systems online remain open to attack.

Hackers are now attacking a dangerous flaw in Sangoma Switchvox. Switchvox is a tool that businesses use to manage their phone systems.
The bug lets an outsider break in without a password. Once inside, the attacker can run commands and take over the whole system. Security teams say the danger is real and growing fast.
The Bug Behind the Attacks
The flaw carries the code name CVE-2026-9586. It sits inside a part of Switchvox that handles phone notifications. This part accepts data from connected phones, including a phone’s IP address.
According to security firm Horizon3, Switchvox takes that phone IP data and feeds it straight into a database command. The system does not clean or check the data first. That mistake opens the door wide for attackers.
Because this part of the system needs no login, anyone can send it a message. If that message hides a harmful database command inside it, the system may run it. Horizon3 showed that hackers can push this even further. They can make the system run commands on the computer itself, not just the database.
Security experts report the flaw scores 9.3 out of 10 on the danger scale used by security experts. That score marks it as critical. An attacker who succeeds can gain full control as the system’s top-level database user.
Researchers at Security Risk Advisors found the same bug on their own. Their team explains that a successful attack can let hackers pull data from the database. It can also let them change user records and gain higher access rights. In the worst case, hackers can open a direct remote channel into the system.
Horizon3 first found the flaw in April 2026 and told Sangoma right away. During testing, the researchers actually found 12 separate flaws in total. This one stood out as the most severe. Sangoma fixed the issues in version 8.4.0.2, which came out on July 14.
Hackers Strike in the Wild
The threat moved from theory to real attacks fast. On August 30, both Horizon3 and a group called Defused Cyber spotted hackers hitting decoy systems set up to catch attackers.
The attacks came from one IP address, 176.65.148.184. The attacker tried to open a direct remote channel into each target system. After breaking in, the attacker checked which programs were running on the machine. The attacker then sent that stolen information to an outside server. The data was hidden using a common encoding trick to avoid easy detection.
Horizon3 warns that the fast pace of these attacks across many decoy systems points to something bigger. The team believes hackers may already be scanning the internet for more weak systems to hit. A search on Shodan, a tool that scans internet-connected devices, found close to 4,000 exposed Switchvox systems. Most of these sit inside the United States.
This news matters because phone systems often connect deep into a company’s network. A hacker who breaks into one weak spot can sometimes reach far more than just phone data.
Time to Patch and Check Your System
Sangoma already built a fix for this flaw. Any business running Switchvox should update to version 8.4.0.2 or a newer version right away. Waiting even a few days could leave a system open to attack.
Updating alone may not be enough. Attackers could have already broken into a system before the update went live. Horizon3 points to a log file called /var/log/switchvox/db-quirks.log as a good place to look for signs of trouble. This file may show strange database activity tied to the attack.
Network teams should also check for any traffic linked to the attacker’s IP address, 176.65.148.184. Horizon3 notes that this traffic often uses port 39323. Spotting a connection to this port could mean a system has already been touched by the attack.
This case shows why phone systems connected to the internet need close attention. A single weak spot lets hackers move from a simple web request all the way to full control of a machine.
Sangoma has already shipped a fix, and our research on the story tells that security teams are urging fast action across the industry. Businesses that skip the update stay open to a threat that is already active and spreading.
The race between attackers and defenders is global. Chinese police researchers are using AI to detect and classify illegal dark web activity by analyzing Chinese-language content and images, providing rare insight into how law enforcement is adopting automation to counter cybercrime. The AI system is designed to overcome the challenges of accessing dark web forums and processing the vast amount of data they contain.