## Overview
CISA has added CVE-2026-9586 to its Known Exploited Vulnerabilities (KEV) list. This vulnerability affects Sangoma Switchvox SMB Edition 8.3 (104997). It allows unauthenticated remote attackers to execute arbitrary SQL statements against the backend PostgreSQL database.
## Technical Details
The vulnerability resides in the /pa endpoint, which processes XML content starting with <PolycomIPPhone>. It directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without proper sanitization or parameterization. This flaw enables attackers to craft a single request that can manipulate the database, potentially leading to remote code execution.
## Impact
An attacker exploiting this vulnerability can perform unauthorized database operations. Since it allows for arbitrary SQL execution, the implications include data theft, data manipulation, and remote code execution. The CVSS score of 9.3 indicates a critical severity, highlighting the urgency of addressing this issue.
## Mitigation
Defenders should prioritize patching affected systems. Sangoma has released updates to address this vulnerability. Organizations using Switchvox should apply these updates immediately to protect against potential exploitation. Additionally, implementing web application firewalls (WAF) and monitoring database logs can help mitigate risks until patches are applied.
CSURFACE Threat Sensor