חזרה לפיד
newsמקור: The Hacker News2.9.2026

תוקפים מנצלים פגיעות קריטית ב-Switchvox להטמעת Reverse Shell

Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

תוקפים מנצלים פגיעות קריטית ב-Switchvox להטמעת Reverse Shell

◆ סיכום AI

תוקפים מנצלים פגיעות אבטחה חמורה (CVE-2026-9586) בפלטפורמת ה-VoIP הארגונית Sangoma Switchvox, המאפשרת הרצת קוד מרחוק ללא אימות (unauthenticated RCE). הפגיעות היא מסוג SQL Injection קריטית, עם ציון CVSS של 9.3. ניצולה מאפשר הטמעת Reverse Shell והרצת קוד שרירותי, ובכך חשיפת מערכות VoIP קריטיות.

# מהמקור

Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution. The vulnerability in question is CVE-2026-9586 (CVSS score: 9.3), a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition 8.3 (104997) that can allow attackers to remotely execute arbitrary code as

#voip-security#rce#sql-injection#vulnerability
קרא במקור