Switchvox is being exploited 47 days after the patch — and patching does not rotate the key they already took
2026-09-02Security
CVE-2026-9586 is an unauthenticated SQL injection in Sangoma Switchvox that gives code execution as the PostgreSQL superuser. Researchers used it to steal the cookie signing key, which lets them forge a session for any user. That key does not change when you install the update.