discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Hackers Exploit Sangoma Switchvox Flaw to Deploy Reverse Shells

Hackers are exploiting a vulnerability in Sangoma Switchvox VoIP platform, leading to remote code execution and reverse shell deployment.

By Bill Toulas·Sep 2·bleepingcomputer.com·1 min read

Intelligence analysis by Qwen 2.5 (3B)

Hackers Exploit Sangoma Switchvox Flaw to Deploy Reverse Shells
Image: bleepingcomputer.com

Hackers are using a SQL injection vulnerability in Sangoma Switchvox to deploy reverse shells, affecting many exposed systems.

Why it matters

This vulnerability could allow attackers to gain full control over exposed Sangoma Switchvox systems, posing a significant security risk.

Hackers found a way to trick a phone system into running bad code, and they're using it to spy on and control the system. They're sending fake messages to the system and then getting back information about what's happening inside.

Analysis

{"heading_1":"The Vulnerability","content_1":"Once attackers have valid credentials, only 37% of their actions are blocked, highlighting the need for comprehensive security measures.","content_2":"Signs of compromise include suspicious statements in /var/log/switchvox/db-quirks.log and network connections to the observed attacker IP, particularly on port 39323.","content_3":"The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments, providing insights into the effectiveness of current security measures.","heading_2":"Exploitation and Impact","heading_3":"Prevention and Detection"}

Key points

  • Hackers are exploiting a SQL injection vulnerability in Sangoma Switchvox to deploy reverse shells.
  • The vulnerability affects many exposed systems, including those in the United States.
  • System administrators are recommended to upgrade to Switchvox version 8.4.0.2 or later to mitigate the risk.
The Upside

By upgrading to the latest version of the phone system, users can protect themselves from this kind of attack.

The Downside

If attackers get past the upgrade, they can still use the system to spy on and control it, so it's important to keep a close eye on any suspicious activity.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecurityvoipsangoma-switchvoxsql-injectionremote-code-execution

Author

Bill Toulas

Intelligence analysis by

Qwen 2.5 (3B)

Published

Sep 2, 2026

Source

bleepingcomputer.com

Share

Topics

securityvoipsangoma-switchvoxsql-injectionremote-code-execution

Related

More from this desk

Sep 2·bleepingcomputer.com

Hackers Exploit Critical JFrog Artifactory Flaw to Forge Admin Tokens

Hackers exploit JFrog Artifactory flaw to create admin tokens, gaining administrative access. JFrog addresses the issue with new versions.

Sep 2·bleepingcomputer.com

Dropbox accounts breached through Lenovo email verification flaw

Dropbox warns some users that unauthorized party accessed their accounts through Lenovo's email verification flaw. 5,000 accounts were accessed, and hacker viewed and downloaded content from some users.

Communicating Under Pressure: Best Practices for Service Providers

Sep 2·cisa.gov

Communicating Under Pressure: Best Practices for Service Providers

CISA and FBI provide guidance on clear, timely, accurate, and audience-appropriate communications during IT and OT outages, emphasizing clarity, accountability, and transparency.

Sep 2·thehackernews.com

How to Secure Enterprise AI: From Adoption to Incident Readiness

How to Secure Enterprise AI: From Adoption to Incident Readiness