CISA added CVE-2026-9586 to the Known Exploited Vulnerabilities catalog on September 2, 2026 — forty-seven days after NVD published the record on July 17. NVD scores the flaw 9.8 (critical) under CWE-89 (SQL injection) and identifies the affected release as Sangoma Switchvox SMB Edition 8.3, build 104997. Per NVD, an unauthenticated remote attacker can execute arbitrary SQL statements against the appliance’s PostgreSQL backend, including reaching remote code execution.
What the flaw is
The root cause NVD describes is the textbook version of CWE-89: an endpoint that handles phone provisioning accepts input without authentication and concatenates a caller-supplied value directly into PostgreSQL queries, with no parameterisation or sanitisation in between. Parameterised queries exist precisely to keep caller-supplied data from being parsed as query structure; where that separation is absent on an unauthenticated path, the database interprets input as instructions.
Two properties compound it. The endpoint requires no credentials, so there is no authentication step to survive — reflected in NVD’s vector as PR:N with no user interaction. And the affected queries run against PostgreSQL rather than an application-layer datastore; NVD’s description carries the consequence past data access into code execution on the host, though the record does not spell out the mechanism by which one becomes the other.
The timeline is the story
This CVE’s dates are more informative than its score:
- July 14, 2026 — Sangoma publishes release notes for Switchvox 8.4.0.2, the release NVD’s reference data points to for this issue.
- July 17, 2026 — NVD publishes the CVE-2026-9586 record, naming 8.3 (104997) as affected.
- September 2, 2026 — CISA adds the CVE to the KEV catalog, confirming observed exploitation.
A fix therefore appears to have been available roughly seven weeks before exploitation was confirmed in the wild. That inference deserves an explicit caveat: our ingested data contains no structured fixed_version field for this CVE. The 8.4.0.2 association comes from the Sangoma release-notes document linked in NVD’s reference list, which is indirect evidence — strong enough to act on by verifying against Sangoma directly, not strong enough to publish as a confirmed fixed-version claim.
Read carefully, this is a patch-gap story rather than a patch-availability story. The defensive failure mode for CVE-2026-9586 was not “no fix existed”; it was that unpatched appliances remained reachable long enough for attackers to find them. Independent disclosure research from SRA Labs and Horizon3.ai is linked from NVD’s reference data for this record, so technical detail has been publicly available since disclosure.
Evidence and confidence
- High confidence — exploitation status and the September 2 KEV date, corroborated by both CISA’s catalog and VulnCheck’s KEV feed. CWE-89 is triple-sourced across NVD, CISA KEV, and VulnCheck KEV.
- Medium confidence — the CVSS 9.8 score, the vector (
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), the technical description, and the affected build identifier. All trace to NVD alone; nothing contradicts them, nothing corroborates them. - Indirect — the 8.4.0.2 fixed-version association, derived from a linked vendor release-notes reference rather than a stated field.
- Unknown — exploitation probability. No EPSS score has been ingested for this CVE.
No field is in conflict between sources.
Why this matters
A PBX is an unusually poor asset to lose. Our source data describes the affected component only as an unauthenticated path into the appliance’s PostgreSQL backend and does not enumerate what that database stores, so the following is analyst assessment rather than a sourced claim: a unified-communications platform’s datastore is the kind of asset that typically holds call detail records, voicemail, and extension and user directories, and telephony platforms commonly hold SIP credentials that would enable toll fraud or call interception as follow-on activity. Treat that as a prompt to establish what your own deployment actually exposes, not as a confirmed inventory of what an attacker obtained. What is straightforwardly true is that NVD places the outcome at code execution on the host, which subsumes whatever the database holds.
Deployment context compounds the exposure. The product’s own naming — SMB Edition — points at small and mid-sized deployments, and our assessment is that this is the segment least likely to maintain an asset inventory that surfaces a superseded networked appliance, or to track KEV additions week by week. The KEV listing carries a remediation obligation under Binding Operational Directive 26-04 for US federal civilian agencies; CISA’s entry directs stakeholders to apply vendor mitigations, evaluate each asset’s internet exposure, and discontinue use of the product where no mitigation is available.
The class-level lesson generalises past this vendor. CVE-2026-9586 and CVE-2026-76461 in Cisco Secure Email Gateway are both CWE-89 unauthenticated SQL injections in network appliances, both scored 9.8, and both on KEV this month — two different vendors shipping the same defect class on a pre-authentication path within weeks of each other. Appliance firmware continues to be where injection bugs of a kind long since designed out of mainstream web frameworks keep surfacing.
CVE-2026-9586 also shares its September 2 KEV date with CVE-2026-82329 in JFrog Artifactory. The two are unrelated technically, but an organisation reconciling its patch backlog against that day’s KEV tranche needs both.
Frequently Asked Questions
What is CVE-2026-9586? A CVSS 9.8 unauthenticated SQL injection vulnerability (CWE-89) in Sangoma Switchvox SMB Edition 8.3 (build 104997) that, per NVD, lets a remote attacker execute arbitrary SQL statements against the appliance’s PostgreSQL backend and reach remote code execution.
Is CVE-2026-9586 being actively exploited? Yes. CISA added it to the Known Exploited Vulnerabilities catalog on September 2, 2026, and VulnCheck’s KEV feed independently records the same date and exploitation status.
Which Switchvox version fixes CVE-2026-9586? NVD’s reference data links Sangoma release notes for Switchvox 8.4.0.2, dated July 14, 2026, but our ingested data carries no structured fixed-version field. Confirm the remediated release against Sangoma’s own advisory before planning an upgrade.
Is authentication required to exploit it? No. NVD’s vector records no required privileges and no required user interaction; the affected endpoint accepts unauthenticated input.
Why was it added to KEV seven weeks after disclosure? KEV addition reflects when CISA obtained evidence of real-world exploitation, not when a vulnerability was disclosed or fixed. The gap here means unpatched appliances were exposed for roughly seven weeks while a fix appears to have already been available.
What should be checked beyond patching? Treat a confirmed-vulnerable, internet-exposed appliance as potentially compromised rather than merely at risk: NVD places the outcome at code execution on the host, and CISA has confirmed exploitation, so an upgrade alone does not answer whether an instance was already reached. Our source data contains no indicators of compromise for this CVE and does not enumerate what the affected database stores — scope the assessment against your own logs, your own deployment’s data, and Sangoma’s guidance rather than a generic checklist.
Severity, vector, weakness classification, affected build, and technical description sourced from the National Vulnerability Database record for CVE-2026-9586; exploitation status, KEV date, and remediation guidance from the CISA Known Exploited Vulnerabilities catalog, with corroborating exploitation status from VulnCheck’s KEV feed. Disclosure research and vendor references linked from NVD: SRA Labs, Horizon3.ai and Sangoma Switchvox 8.4.0.2 release notes. Aggregated September 17, 2026. See more vulnerability intelligence.