Your Phone System Just Handed Attackers the Keys: The Switchvox and SonicWall Exploits Active Right Now
Two vulnerabilities confirmed as actively exploited. Both targeting infrastructure that sits in small business server rooms and comms cupboards across the UK. Both patched. Both, in a significant number of cases, still unpatched in the wild.
Let us work through what the data shows.
Story One: Your Phone System Is an Open Door
Sangoma Switchvox is an enterprise VoIP platform. A business phone system. The kind of thing a 30-person professional services firm installs, configures once, and then forgets about for three years while the vendor quietly releases security updates nobody applies.
CVE-2026-9586 is a SQL injection vulnerability in Switchvox. SQL injection means an attacker can send a specially crafted request to the system and manipulate the underlying database directly. In this case, the flaw goes further: it allows unauthenticated remote code execution. No username. No password. One crafted request to the right endpoint and an attacker has a working reverse shell on your phone system.
A reverse shell, for those unfamiliar with the term: it is a connection that your compromised system initiates back to the attacker’s server. It bypasses most inbound firewall rules because the traffic appears to originate from inside your network. Once established, the attacker has command-line access to the device.
CISA added this to its Known Exploited Vulnerabilities catalogue on 2 September 2026. That designation means CISA has confirmed real-world exploitation, not theoretical risk. Approximately 4,000 Switchvox instances are exposed to the internet. The patch exists. The question is whether it has been applied to yours.
If Switchvox is your phone system, contact whoever manages it today. Not this week. Today.
Story Two: The VPN Gateway With a Perfect Vulnerability Score
SonicWall’s SMA1000 appliances are used as secure remote access gateways: the device your staff connect through when working from home, the system that sits between the internet and your internal network. A compromised SMA1000 is not a minor incident. It is a direct path into everything behind it.
CISA added two SMA1000 vulnerabilities on the same day.
CVE-2026-83548 carries a CVSS score of 10.0. The maximum possible. It is a server-side request forgery (SSRF) vulnerability, meaning an attacker can send requests through the SMA1000 appliance as if they were the appliance itself, gaining unauthorised access to internal systems and sensitive functionality. No authentication required.
CVE-2026-83549 is an OS command injection vulnerability. An authenticated administrator account can use it to execute arbitrary operating system commands, resulting in remote code execution. The two flaws are assessed as forming a potential attack chain: use the unauthenticated SSRF flaw to gain initial access or escalate privileges, then use the command injection to achieve full remote code execution.
SonicWall has a documented history with ransomware groups. Its appliances have been used as entry points in ransomware campaigns previously. This is not the first time SMA series products have appeared in CISA’s KEV catalogue. The pattern is established. The attacker methodology is known. The patch, again, exists.
SonicWall released updates addressing both vulnerabilities. If your SMA1000 appliance is internet-facing and unpatched, it is an active target.
The Pattern the Data Confirms
These two incidents share a structure that appears repeatedly in the vulnerability data.
First: the vulnerable product is infrastructure, not endpoint software. Not a desktop application that gets updated through Windows Update. A physical or virtual appliance that requires deliberate action to patch, often by a managed service provider or IT support company on a scheduled maintenance cycle.
Second: the exploitation requires no credentials. Both the Switchvox SQL injection and the SonicWall SSRF flaw are unauthenticated. The attacker does not need to steal a password first. They need network access to the device and an unpatched instance.
Third: the patches predate the active exploitation. This is not zero-day exploitation where defenders had no warning. These are known vulnerabilities with available fixes. The organisations being compromised today are being compromised because patching did not happen.
The NCSC’s guidance on vulnerability management is consistent on this point: prioritise patching of internet-facing systems and do not rely on scheduled maintenance windows for critical security updates. A CVSS 10.0 flaw on an internet-facing gateway is not a next-maintenance-window problem.
Why This Gives Your Business an Edge
There is a straightforward competitive signal available here, particularly if your business handles client data or operates in a supply chain where larger organisations assess your security posture.
Being able to demonstrate that your internet-facing infrastructure is patched within 24 to 48 hours of a critical vulnerability disclosure is a measurable, verifiable security capability. It is not compliance theatre. It is evidence of an operational patching process that functions.
Procurement questionnaires increasingly ask about patch management timelines. Cyber Essentials, which the UK government requires for certain public sector contracts, includes patch management as a core control. The standard requires that high-risk vulnerabilities are patched within 14 days. A CVSS 10.0 flaw on an internet-facing system is, by definition, high risk.
If your current IT support cannot tell you whether your systems are patched within 24 hours of a major vulnerability disclosure, you have a measurable gap. That gap is the same one attackers are currently exploiting.
Making the Business Case
Three points worth taking to anyone who controls the IT budget.
The cost asymmetry is stark. A patch applied during a 30-minute maintenance window costs IT support time. A ransomware incident via an unpatched SonicWall gateway costs forensics, recovery, potential ICO notification, client notification, reputational damage, and downtime. These are not comparable numbers.
The regulator has a position on this. The ICO takes patch management seriously in the context of GDPR Article 32, which requires organisations to implement appropriate technical measures to ensure security. Failure to patch a known, critical vulnerability on an internet-facing system is difficult to defend as appropriate technical measure in the event of a breach.
Your MSP has an obligation. If you pay a managed service provider to manage your infrastructure, patching critical vulnerabilities on internet-facing systems is part of that service. If your MSP cannot confirm within 24 hours whether CVE-2026-83548 and CVE-2026-9586 have been addressed, that is a contractual and service quality conversation worth having.
What to Do Before Friday
Four specific actions. All of them achievable without specialist security expertise.
1. Identify whether you run either product. Sangoma Switchvox (phone system) or SonicWall SMA1000 (remote access gateway). If you are not certain, ask whoever manages your IT infrastructure.
2. Confirm patch status in writing. Ask your IT support or MSP to confirm by email that CVE-2026-9586 (Switchvox) and CVE-2026-83548 / CVE-2026-83549 (SonicWall SMA1000) have been patched. Get the version numbers. A verbal assurance is not sufficient.
3. If patching cannot be confirmed, take the device offline. An unpatched internet-facing device with a confirmed active exploit is a more serious risk than a temporary service disruption. This is not a popular decision, but it is the correct one.
4. Review your patch management SLA with your IT provider. Ask explicitly: what is the timeline for applying critical security patches to internet-facing infrastructure? If the answer is longer than 14 days, or if there is no defined answer, that requires a contract conversation.
The vulnerabilities are confirmed. The patches exist. The exploits are active. What happens next depends on whether someone takes action.
Before you go: follow the show wherever you listen, leave a rating or review, drop a comment with your thoughts, and share this with someone who manages IT for a small business. They need to know about this today.