Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution. [...]
KEV ✓
EPSS 0.01
CVE-2026-9586
Sangoma
telekomunikace
US
2 zdrojů
tg: incident
tg: zneužíváno
tg: zranitelnost
tp: malware
BleepingComputer
2. 9. 23:00
·
CISA KEV
2. 9. 02:00
CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-9586 Sangoma Switchvox SQL Injection Vulnerability CVE-2026-48710 Kludex Starlette HTTP Request/Response Smuggling Vulnerability CVE-2026-49869 Kestra OSS OS Command Injection Vulnerability CVE-2026-59822 BerriAI LiteLLM Improper Authentication Vulnerability CVE-2026-82329 JFrog Artifactory Improper Authentication Vulnerability CVE-2026-83548…
KEV ✓
EPSS 0.02
CVE-2026-48710
CVE-2026-49869
CVE-2026-59822
CVE-2026-82329
CVE-2026-83548
CVE-2026-83549
CVE-2026-9586
Sangoma
SonicWall
JFrog
Kestra
veřejná správa
US
tg: zneužíváno
tg: zranitelnost
CISA Advisories
· 2. 9. 14:00