PatchSiren

Sangoma CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Sangoma CVE published 2026-07-17

CVE-2026-9588

A stored cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997) within the voicemail notification template functionality. The submit_modify_voicemail_template endpoint fails to properly sanitize HTML content supplied by authenticated users, allowing malicious JavaScript supplied through the template_text parameter to be stored server-side and subsequently rendered to [truncated]

HIGH Sangoma CVE published 2026-07-17

CVE-2026-9587

CVE-2026-9587 is a HIGH severity vulnerability in Sangoma Switchvox SMB Edition 8.3. The play_file functionality accepts user-controlled input through the sound_path parameter and fails to properly validate file paths before accessing the underlying filesystem. By supplying absolute paths, an authenticated attacker can retrieve files outside the intended directory scope. This vulnerability has a CVSS scor [truncated]

CRITICAL Sangoma CVE published 2026-07-17

CVE-2026-9586

A critical SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3. The /pa endpoint processes XML content and directly concatenates user-controlled input into PostgreSQL queries without sanitization, allowing unauthenticated remote attackers to execute arbitrary SQL statements. This vulnerability has a CVSS score of 9.3 and is considered CRITICAL. Organizations using Sangoma Switchvox SMB [truncated]

HIGH Sangoma CVE published 2026-07-17

CVE-2026-9585

CVE-2026-9585 is a HIGH severity vulnerability in Sangoma Switchvox SMB Edition version 8.3 (104997). The application fails to properly sanitize the portal parameter supplied to the invalid_browser and invalid_browser_login handlers, allowing unauthenticated reflected cross-site scripting. This vulnerability allows attacker-controlled script execution within a victim's browser. Administrators and users of [truncated]

Known exploited Sangoma CVE published 2026-02-03

CVE-2025-64328

CVE-2025-64328 is a Sangoma FreePBX operating-system command injection vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2026-02-03. That listing means the issue is considered actively exploited in the wild, so defensive action should be prioritized immediately. The supplied corpus does not include affected versions, CVSS scoring, or vendor advisory text, so remediation shoul [truncated]

Known exploited Sangoma CVE published 2026-02-03

CVE-2019-19006

CVE-2019-19006 is a Sangoma FreePBX improper authentication vulnerability that CISA added to the Known Exploited Vulnerabilities (KEV) catalog on 2026-02-03. The available source corpus does not provide detailed exploit mechanics, but it does confirm this issue is considered known exploited and that remediation should follow vendor guidance. CISA’s KEV entry also points to a Sangoma/FreePBX vendor note ti [truncated]

Known exploited Sangoma CVE published 2025-08-29

CVE-2025-57819

CVE-2025-57819 is a Sangoma FreePBX authentication bypass vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2025-08-29. Because it is in KEV, defenders should treat it as an active-exploitation risk and move quickly to vendor-directed mitigation, patching, or removal if mitigation is not possible.