Skip to content
feed: live
>_0dayNews
threat intel

Switchvox Flaw Exploited for Unauthenticated RCE

Attackers are exploiting a critical vulnerability in Sangoma Switchvox enterprise VoIP to deploy reverse shells without credentials. No CVE identifier publicly disclosed yet.

Switchvox Flaw Exploited for Unauthenticated RCE
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
fuseMarisol "Fuse" Delgado·Published ·1 min read

Attackers are exploiting a critical vulnerability in Sangoma Switchvox, an enterprise VoIP platform, to deploy reverse shells on affected systems without supplying any credentials. The Hacker News reported active exploitation as of September 2, 2026.

Switchvox is a commercial IP PBX product used by enterprises for voice and unified communications. The flaw allows unauthenticated remote code execution. Attackers reaching an exposed Switchvox instance can execute arbitrary commands on the host without prior authentication, and current attacks are using that access to drop reverse shells for persistent access and lateral movement.

No CVE identifier has been publicly disclosed in available reporting as of publication. Severity has been characterized as critical.

What to do

If you’re running Sangoma Switchvox in your environment:

Check whether the management interface is internet-exposed. There is no reason for Switchvox’s administrative interface to be reachable from outside your organization’s perimeter. If it is, that changes immediately: restrict access to internal networks and trusted management hosts.

Check for signs of compromise. Reverse shell activity produces outbound network connections from the Switchvox host to attacker-controlled infrastructure on unusual ports. Look for unexpected outbound connections from your PBX host, unusual processes spawned by the web server or application process, and any new accounts or configuration changes you didn’t make.

Apply vendor patches when available. Monitor Sangoma’s security advisories for a patch and CVE identifier. If a patch is available in your update channel, apply it.

Enterprise VoIP infrastructure sits at the intersection of several risks: it handles communications, often has privileged network access, and may be administered inconsistently compared to core IT systems. A reverse shell on your PBX is persistent access to a system that talks to everything.

Context

Active exploitation before a CVE is assigned or a patch is widely available narrows the response window to what you can control: network exposure and detection. PaperCut active intrusions and the SonicWall zero-days confirmed earlier today follow the same pattern: enterprise infrastructure with administration interfaces that have no business facing the internet being exploited through them.

The exploit itself is not the only variable you control. Exposure is.

Source: The Hacker News.

Found this useful? Share it.