
A Critical Business Phone System Flaw Is Under Active Attack, and It Tests Your HIPAA Network Segmentation
CISA added CVE-2026-9586, an unauthenticated SQL injection flaw in the Sangoma Switchvox business phone system, to its Known Exploited Vulnerabilities catalog on September 2, 2026, after honeypots caught attackers deploying reverse shells. Roughly 4,000 Switchvox systems are reachable from the open internet, according to Shodan.
Read the Article
















