[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2026-9586":6},{"stargazers_count":4,"fetched_at":5},7,"2026-09-02T23:44:56.672Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":44,"aliases":54,"duplicate_of":9,"upstream":55,"downstream":56,"duplicates":57,"related":58,"reserved_at":9,"published_at":59,"modified_at":60,"state":61,"summary":62,"references_raw":72,"kevs":94,"epss":105,"epss_history":107,"metrics":249,"affected":260},"CVE-2026-9586","An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with \u003CPolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-89","Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.","weakness","Stable","Base","High",[20,24,28,32,36,40],{"id":21,"name":22,"techniques":23},"CAPEC-108","Command Line Execution through SQL Injection",[],{"id":25,"name":26,"techniques":27},"CAPEC-109","Object Relational Mapping Injection",[],{"id":29,"name":30,"techniques":31},"CAPEC-110","SQL Injection through SOAP Parameter Tampering",[],{"id":33,"name":34,"techniques":35},"CAPEC-470","Expanding Control over the Operating System from the Database",[],{"id":37,"name":38,"techniques":39},"CAPEC-66","SQL Injection",[],{"id":41,"name":42,"techniques":43},"CAPEC-7","Blind SQL Injection",[],[45],{"_key":46,"name":47,"source":48,"url":49,"maturity":50,"reliability_score":51,"verified":52,"type":9,"platforms":53,"requires_auth":9,"exploitdb":9,"metasploit":9},"REF_9D51E821DE7F23EA","Exploit Reference (horizon3.ai)","reference","https://horizon3.ai/attack-research/disclosures/cve-2026-9586-sangoma-switchvox-rce/#","unknown",0.2,false,[],[],[],[],[],[],"2026-07-17T15:57:42.879Z","2026-09-02T19:58:24.587Z","Analyzed",{"cisa_kev":63,"cisa_ransomware":52,"cisa_vendor":64,"epss_severity":65,"epss_score":66,"severity":67,"severity_score":68,"severity_version":69,"severity_source":70,"severity_vector":71,"severity_status":61},true,"Sangoma","low",0.01088,"critical",9.8,"v3.1","nvd","CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",[73,79,84,88],{"url":74,"sources":75,"tags":77},"https://sangomakb.atlassian.net/wiki/spaces/Switchvox/pages/1802371073/Switchvox+-+Release+Notes+Version+8.4.0.2+July+14+2026",[76,70],"cve.org",[78],"Release Notes",{"url":80,"sources":81,"tags":82},"https://labs.sra.io/posts/switchvox/",[76,70],[83],"Third Party Advisory",{"url":49,"sources":85,"tags":86},[76,70],[83,87],"Exploit",{"url":89,"sources":90,"tags":91},"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-9586",[76,70],[92,83,93],"Government Resource","US Government Resource",[95],{"source":96,"vendor":64,"product":97,"date_added":98,"vulnerability_name":99,"short_description":100,"required_action":101,"due_date":102,"known_ransomware_campaign_use":103,"notes":104,"exploitation_type":9},"cisa","Switchvox","2026-09-02","Sangoma Switchvox SQL Injection Vulnerability","Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.","Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","2026-09-05","Unknown","https://sangomakb.atlassian.net/wiki/spaces/Switchvox/pages/1802371073/Switchvox+-+Release+Notes+Version+8.4.0.2+July+14+2026 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-9586",{"date":98,"score":66,"percentile":106},0.63028,[108,112,114,117,120,123,126,129,132,135,138,141,144,147,150,153,156,159,162,165,168,171,174,177,180,183,186,189,192,195,198,201,204,207,210,213,216,219,223,226,229,232,235,238,241,244,248],{"date":109,"score":110,"percentile":111},"2026-07-18",0.00411,0.33259,{"date":113,"score":110,"percentile":111},"2026-07-19",{"date":115,"score":110,"percentile":116},"2026-07-20",0.33338,{"date":118,"score":110,"percentile":119},"2026-07-21",0.33345,{"date":121,"score":110,"percentile":122},"2026-07-22",0.33529,{"date":124,"score":110,"percentile":125},"2026-07-23",0.33531,{"date":127,"score":110,"percentile":128},"2026-07-24",0.33549,{"date":130,"score":110,"percentile":131},"2026-07-25",0.33627,{"date":133,"score":110,"percentile":134},"2026-07-26",0.33617,{"date":136,"score":110,"percentile":137},"2026-07-27",0.33595,{"date":139,"score":110,"percentile":140},"2026-07-28",0.33653,{"date":142,"score":110,"percentile":143},"2026-07-29",0.33672,{"date":145,"score":110,"percentile":146},"2026-07-30",0.33737,{"date":148,"score":110,"percentile":149},"2026-07-31",0.33761,{"date":151,"score":110,"percentile":152},"2026-08-01",0.3377,{"date":154,"score":110,"percentile":155},"2026-08-02",0.33772,{"date":157,"score":110,"percentile":158},"2026-08-03",0.33788,{"date":160,"score":110,"percentile":161},"2026-08-04",0.33762,{"date":163,"score":110,"percentile":164},"2026-08-05",0.33734,{"date":166,"score":110,"percentile":167},"2026-08-06",0.33765,{"date":169,"score":110,"percentile":170},"2026-08-07",0.33807,{"date":172,"score":110,"percentile":173},"2026-08-08",0.33811,{"date":175,"score":110,"percentile":176},"2026-08-09",0.33796,{"date":178,"score":110,"percentile":179},"2026-08-10",0.33808,{"date":181,"score":110,"percentile":182},"2026-08-11",0.33901,{"date":184,"score":110,"percentile":185},"2026-08-12",0.33985,{"date":187,"score":110,"percentile":188},"2026-08-13",0.34024,{"date":190,"score":110,"percentile":191},"2026-08-14",0.34079,{"date":193,"score":110,"percentile":194},"2026-08-15",0.34205,{"date":196,"score":110,"percentile":197},"2026-08-16",0.34234,{"date":199,"score":110,"percentile":200},"2026-08-17",0.34171,{"date":202,"score":110,"percentile":203},"2026-08-18",0.34195,{"date":205,"score":110,"percentile":206},"2026-08-19",0.34381,{"date":208,"score":110,"percentile":209},"2026-08-20",0.34442,{"date":211,"score":110,"percentile":212},"2026-08-21",0.34476,{"date":214,"score":110,"percentile":215},"2026-08-22",0.34492,{"date":217,"score":110,"percentile":218},"2026-08-23",0.3442,{"date":220,"score":221,"percentile":222},"2026-08-24",0.00695,0.50205,{"date":224,"score":221,"percentile":225},"2026-08-25",0.50238,{"date":227,"score":221,"percentile":228},"2026-08-26",0.50321,{"date":230,"score":221,"percentile":231},"2026-08-27",0.50369,{"date":233,"score":221,"percentile":234},"2026-08-28",0.50031,{"date":236,"score":221,"percentile":237},"2026-08-29",0.50069,{"date":239,"score":221,"percentile":240},"2026-08-30",0.50464,{"date":242,"score":221,"percentile":243},"2026-08-31",0.50477,{"date":245,"score":246,"percentile":247},"2026-09-01",0.00434,0.36259,{"date":98,"score":66,"percentile":106},[250,255],{"source":76,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":9,"cvss_v4_0":251},{"baseScore":252,"baseSeverity":253,"vectorString":254,"impactScore":9,"exploitabilityScore":9},9.3,"CRITICAL","CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",{"source":70,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":256,"cvss_v4_0":258},{"baseScore":68,"baseSeverity":253,"vectorString":71,"impactScore":68,"exploitabilityScore":257},10,{"baseScore":252,"baseSeverity":253,"vectorString":259,"impactScore":9,"exploitabilityScore":9},"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",[261,273],{"ecosystem":9,"name":262,"vendor":263,"product":262,"cpe_part":264,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":265},"switchvox","sangoma","a",[266],{"version":267,"is_range":63,"range_type":268,"version_start":269,"version_start_type":270,"version_end":271,"version_end_type":272,"fixed_in":9},"gte8.2.2.1_lt8.4.0.2","cpe","8.2.2.1","including","8.4.0.2","excluding",{"ecosystem":9,"name":274,"vendor":263,"product":275,"cpe_part":264,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":276},"Switchvox SMB Edition","switchvox smb edition",[277],{"version":278,"is_range":63,"range_type":76,"version_start":279,"version_start_type":270,"version_end":271,"version_end_type":272,"fixed_in":9},">= 8.3 (104997), \u003C 8.4.0.2","8.3 (104997)"]