ALMC
ALMC Security Logo - Mantenimiento Web, Programación Web Barcelona, Servidores Barcelona, Ciberseguridad Barcelona
  • English
    Español English Français Català

Quick search

Results without leaving the page.

Type to search ALMC products, services, articles and tools.

View all results
Habla a nuestro AgenteIA · respuestas al instante · 24/7
  • HomeALMC
  • ALMCAbout Us
  • ALMC SECURITY S.L.U.Contact
  • Posts
    • Posts
    • Categorías
    • Etiquetas
    • Estados
  • Soluciones
    • Desarrollo Web en Lleida — Diseño a Medida que Vende
    • Tienda Online a Medida — E-commerce que Vende de Verdad
    • Chatbot IA para Empresas — Automatiza tu Atención al Cliente
    • Automatización de Procesos para Empresas — Menos Tareas, Más Resultados
    • Desarrollo de Apps Móviles — iOS y Android a Medida
  • Services
    • Cybersecurity
      • Security Audits and Pentesting
      • Monitoring & Incident Response (SIEM)
      • System & Server Hardening
      • Compliance Consulting (GDPR, ENS, ISO 27001)
      • Cloud Security (AWS, Azure, Google Cloud)
    • Programming
      • Full Stack Web Development Laravel, Vue.js
      • Process Automation (Scripts and Bots)
      • Process Automation Scripts and Bots
      • API Integrations & Microservices
      • Code Maintenance and Optimization
    • Servers
      • Server Management & Monitoring
      • Cloud Migration (AWS, Azure, Google Cloud)
      • Performance Optimization
      • Virtualization & Containers (Docker, Kubernetes)
      • Backup & Disaster Recovery Plans
    • Website Virus Removal
    • Website Maintenance
      • WordPress Maintenance
      • PrestaShop Maintenance
      • Magento Maintenance
      • Joomla Maintenance
      • Drupal Maintenance
      • Shopify Maintenance
      • Wix Maintenance
      • Concrete5 Maintenance
      • HTML Maintenance
      • PHP Maintenance
      • JavaScript Maintenance
      • Python Maintenance
    • Website Repair
      • Hacked site cleanup
      • Fix WordPress
      • Fix PrestaShop
      • Fix Magento
      • Fix Joomla
      • Fix Drupal
      • Fix Shopify
      • Fix OpenCart
      • Fix Moodle
  • Industries
    • 3D Printing & Additive
    • Accounting
    • Advertising & Marketing
    • Aerospace & Defense
    • Agriculture
    • Architecture & Engineering
    • Arts & Culture
    • Automotive
    • Banking & Finance
    • Biomedical Research
    • Biotechnology
    • Breweries
    • Call Centers & BPO
    • Chemicals
    • Cleaning Services
    • Clinics
    • Cloud Providers
    • Construction
    • Consulting
    • Cosmetics & Beauty
    • Courier & Last Mile
    • Cybersecurity
    • Data Centers
    • Defense & Security
    • E-Commerce
    • EdTech
    • Education (K-12)
    • Electrical Equipment
    • Electronics
    • Environmental NGOs
    • Environmental Services
    • Events & Conferences
    • Facilities Management
    • Fashion & Luxury
    • FinTech
    • Fishing & Aquaculture
    • Food & Beverage Manufacturing
    • Forestry
    • Freight Transport
    • Furniture
    • Gaming
    • Government & Public Administration
    • GovTech
    • Gyms & Fitness Centers
    • Healthcare Providers
    • HealthTech
    • Higher Education
    • Home Appliances
    • Home Services
    • Hospitality
    • Hospitals
    • Human Resources
    • Insurance
    • InsurTech
    • Internet & Web Services
    • Investment & Asset Management
    • IT Services
    • Jewelry
    • Landscaping & Gardening
    • Legal Services
    • Logistics & Supply Chain
    • Machinery
    • Maritime
    • Media & Entertainment
    • Medical Devices
    • Metals
    • Mining
    • Music Industry
    • Nonprofit & NGOs
    • Oil & Gas
    • Paper & Print Media
    • Paper & Pulp
    • Pharmaceuticals
    • Photography & Video
    • Plastics
    • Postal & Courier
    • Printing
    • Private Education & Academies
    • Property Development
    • Property Management
    • PropTech
    • Public Safety & Emergency
    • Publishing
    • Rail & Public Transport
    • Real Estate
    • Real Estate Agencies
    • Religious Organizations
    • Renewable Energy
    • Research & Development
    • Research Labs
    • Restaurants & Food Service
    • Retail
    • Security Services
    • Semiconductors
    • Software Development
    • Sports & Fitness
    • Sports Clubs
    • Staffing & Recruitment
    • Telecommunications
    • Textile & Apparel
    • Tobacco
    • Toys
    • Travel & Tourism
    • Travel Agencies
    • Utilities
    • Veterinary & Animal Care
    • Warehousing
    • Waste Management
    • Water Treatment
    • Wholesale
    • Wineries & Vineyards
  • Tools
    • Network
      • What's my IP
      • WHOIS IP
      • Domain WHOIS
      • Geolocate IP
      • DNS Lookup
      • DNS Propagation
      • ASN Lookup
      • Reverse Lookup
      • Domain monitoring
    • Image Compressor
    • MCP Servers
  • Products
    • Whatsboost
      • Whatsboost PrestaShop
      • Whatsboost WordPress
      • Whatsboost Shopify
    • Ulix
      • Extension QR para navegador
    • Chatbot
      • Chatbot WhatsApp
      • Chatbot Instagram
      • Chatbot Facebook
      • Chatbot TikTok
    • VeriFactu
    • Web TV
      • Mis pantallas
      • Vincular nueva TV
      • Dispositivos vinculados
      • Releases APK
      • Pantallas por cliente
    • Control de Fichajes

5 News at ALMC
  • Inauguration of the... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    Inauguration of the...It was a very busy and special day. 30 Jun 2025
  • Website Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    WebsiteI recover the domain I had in the past and set up... 01 Jun 2025
  • Signing of the Lease... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    Signing of the Lease...After spending some time looking for premises, my... 01 Jun 2025
  • ALMC returns and com... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    ALMC returns and com...We reactivate the brand with ALMC SECURITY SL (CIF... 23 Apr 2025
  • feb. 2025 Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    feb. 2025The decision to start entrepreneurship again was b... 01 Feb 2025

View all news

Critical Switchvox RCE: Patch Now to Protect Your VoIP Servers

  1. Home
  2. Blog
  3. Categories
  4. Cybersecurity
  5. Critical Switchvox RCE: Patch Now to Protect...
  • All articles
  • Categories
  • Tags
  • Statuses

Critical Switchvox RCE: Patch Now to Protect Your VoIP Servers

Urgent: Unpatched Switchvox Systems Are Under AttackAdministrators of VoIP systems and IT managers across Spain are facing a new security alert. A cri...

Urgent: Unpatched Switchvox Systems Are Under Attack

Administrators of VoIP systems and IT managers across Spain are facing a new security alert. A critical vulnerability in Sangoma Switchvox, a widely used PBX platform, is being actively exploited in the wild. The flaw allows remote attackers to execute arbitrary code without any credentials, and confirmed attacks have been observed since late August 2026. If you manage a Switchvox instance, especially one exposed to the internet, immediate action is required.

Shield protecting a vulnerable telephone switchboard from a red glowing cable

Understanding the Vulnerability: CVE-2026-9586

The issue, tracked as CVE-2026-9586, carries a CVSS score of 9.3, reflecting its severity. The root cause lies in the HTTP endpoint /pa, which processes XML requests. Specifically, the PhoneIP parameter is incorporated into PostgreSQL queries without proper sanitization or parameterization—a classic SQL injection flaw (CWE-89). An attacker can exploit this to run arbitrary database queries, escalate privileges to PostgreSQL superuser, and ultimately achieve remote code execution on the underlying system.

This is not a theoretical risk. Security researchers have documented real-world attacks that use this vulnerability to deploy reverse shells, giving attackers interactive access to the server. The observed post-exploitation activity includes reconnaissance commands encoded in Base64 to enumerate running processes, indicating a deliberate attempt to understand the environment and potentially pivot to other systems.

Immediate Steps to Mitigate Risk

If you are running a version of Switchvox prior to 8.4.0.2, you are vulnerable. The vendor released this patched version on July 14, 2026, which addresses the SQL injection and includes additional security fixes. Your first priority should be to update to 8.4.0.2 or later, especially if your Switchvox instance is accessible from the internet or from untrusted networks.

While you plan the update, consider reducing your attack surface:

  • Restrict access to the /pa endpoint and the web management interface using firewall rules or access control lists.
  • Place the system behind a VPN or segment it from the rest of your network to limit lateral movement.
  • Monitor outbound connections for anomalies, such as reverse shell traffic or connections to known malicious IP addresses like 176.65.148.184, which has been linked to this exploitation.

Detecting Signs of Compromise

Even if you patch promptly, you should check whether your system has already been compromised. Look for indicators of post-exploitation activity:

  • Unusual processes, such as nc (netcat) or unexpected bash invocations from web services.
  • Log entries in /var/log/switchvox/db-quirks.log that show SQL injection attempts or suspicious database queries.
  • Evidence of file downloads or command execution via curl or wget.

If you find any signs of compromise, your response must go beyond patching. Rotate all credentials associated with the system, including database passwords and administrative accounts, and conduct a thorough forensic analysis to determine the extent of the intrusion. Consider engaging a cybersecurity professional to help with the investigation.

Why This Matters for Businesses in Spain

VoIP systems are the backbone of modern business communications, and many small and medium-sized enterprises (SMEs) in Spain rely on Sangoma Switchvox for their telephony needs. The exploitation of this vulnerability highlights a broader trend: attackers are increasingly targeting internet-facing infrastructure with known vulnerabilities. The fact that this flaw has been exploited in the wild within weeks of the patch’s release underscores the importance of timely updates.

For companies in Lleida, Barcelona, or anywhere in Spain, the risk is not hypothetical. An attacker who gains control of your PBX can intercept calls, access voicemail, or use the system as a launching pad for further attacks on your network. The cost of a breach—both in terms of data loss and regulatory fines under GDPR—far outweighs the effort required to apply a security patch.

Strengthening Your Overall Server Security

This incident is a reminder that no single security measure is foolproof. A layered approach is essential. One effective strategy is to centralize your server protection with a solution like Abuse Shield, which automatically blocks malicious IPs, manages fail2ban across multiple machines, and shares a reputation feed across all your servers. By integrating such a tool, you can proactively defend against known malicious actors and reduce the window of exposure when new vulnerabilities emerge.

While patching is critical, it is equally important to have a robust monitoring and response plan. Regularly review your security logs, keep all software up to date, and consider using intrusion detection systems. For businesses without a dedicated security team, managed security services can provide the expertise needed to stay ahead of threats.

Conclusion

The exploitation of CVE-2026-9586 is a clear call to action for all Switchvox administrators. Update to version 8.4.0.2 or later immediately, check for signs of compromise, and reinforce your security posture. In today’s threat landscape, proactive measures are not optional—they are essential for business continuity and compliance. Do not wait for an attacker to knock on your door.

Related

  • Critical JFrog Artifactory Flaw: Protect Your Software Supply Chain
  • Chrome Zero-Day: Update Now to Patch Actively Exploited Flaw
  • Chrome Zero-Day: Urgent Patch for Actively Exploited V8 Flaw
  • Desarrollo web

Put these ideas into practice

Talk to ALMC about a solution for your business. Explore your options or contact our team.

Soluciones ALMC

Full Stack Web Development Laravel, Vue.js
Performance Optimization
Virtualization & Containers (Docker, Kubernetes)
Backup & Disaster Recovery Plans
Monitoring & Incident Response (SIEM)
Relacionados
  • CISA KEV Update: Six Actively Exploited Flaws Including NetScaler, Linux, SQL Server
    Cybersecurity · 24 minutes ago
  • SLEEPWALKER Backdoor: A Stealthy Threat for Windows Servers
    Cybersecurity · 24 minutes ago
  • SLEEPWALKER Backdoor: A Stealthy Threat for Windows Servers
    Cybersecurity · 24 minutes ago
  • Zimbra CVE-2026-73570: Patch Now, Then Hunt for Intrusions
    Cybersecurity · 24 minutes ago
  • GeoServer RCE: Critical Flaw CVE-2024-36401 Under Active Attack
    Cybersecurity · 24 minutes ago
  • Critical JFrog Artifactory Flaw: Protect Your CI/CD Supply Chain
    Cybersecurity · 1 hour ago
Servidores MCP Destacados
  • stdout-mcp-server
    Development
  • MCP Toolbox for Databases
    Official 🌟 Oficial
  • SolTracker
    Development
  • Unstructured
    Official 🌟 Oficial
  • Reexpress
    Search
  • Petstore MCP Server & Client
    Development
  • MCP Installer
    Development
  • AITable
    Database
  • MCP Interactive
    Communication
Ver todos los servidores MCP
Cybersecurity · Blog Brain · 2026-09-08
Cerrar panel
Your ecosystem

SaaS applications

Open each workspace directly with your ALMC account.

My account Create account
VeriFactuVerified invoicingAbuse ShieldWeb securityWhatsBoostSales and CRMCommerceStore and POSEmail AISmart emailWebTVDigital signageTime trackingWorking-time controlPrintFlowPrint workflows
Agente Smith · ALMCAgente IA propio on-premise

Hola 👋 Soy Smith, el agente IA de ALMC. Pregúntame sobre ciberseguridad, IA, desarrollo a medida o nuestros productos SaaS.

¿Prefieres hablar con persona? Contacto humano

ALMC access centre

One account · All your services

Start wherever you want.

Create an account to centralise your services, or ask for guidance if you do not know what you need yet.

Create account Talk to ALMC

Explore by product

VeriFactuInvoicingAbuse ShieldSecurityWhatsBoostSalesCommerceStore and POSEmail AIAutomationWebTVDigital signage

Sign in to your account.

The same sign-in brings together your services, team and billing.

Enter my panelAccess your services, team and billing.
Sign in

Not a client yet? Create an account

ALMC Security Logo

Experts in cybersecurity, custom Laravel development, and server management. We deliver robust, secure, and personalized technological solutions.

Latest News

Inauguration of the first office in Lleida of ALMC SECURITY SL
Inauguration of the first office in Lleida of ALMC...
30 Jun 2025
Website
01 Jun 2025
Signing of the Lease Contract
Signing of the Lease Contract
01 Jun 2025

Main Services

  • desarrollo web lleida
  • tienda online a medida
  • chatbot ia empresa
  • automatización procesos empresa
  • desarrollo aplicaciones móviles

Suite SaaS

  • PrintFlow (copisterías)
  • WebTV (cartelería)
  • VeriFactu (facturación)
  • Fichaje horario

Contact

  • Rambla de Ferran, 37, 25007 Lleida

  • +34 614 443 757

  • info@almc.es

Follow Us

Useful links

  • About us
  • Contact
  • Reserva cita
  • Hacked website repair
  • Website maintenance
  • Website repair
  • Tools
  • What is my IP
  • Compress images
  • Site search
  • Blog

© Copyright 2026. ALMC SECURITY S.L.U.

  • Legal
      • Privacy Policy
      • Terms and Conditions of Service
      • Legal Notice and Corporate Information
      • Cookie Policy
  • Resources
    • Blog
    • Sitemap

ALMC

Legal

This site only uses first-party cookies and local browser storage, and only to make it work: keeping your session, protecting forms, remembering your language and not showing you this notice again. We use no analytics or advertising cookies, there are no third-party cookies and we do not build profiles. As strictly necessary technical cookies, they are exempt from consent under Article 22.2 of the Spanish LSSI-CE: this notice is informative and the button only stops it from appearing again. You can delete or block them from your browser, though some features may then stop working. Cookie Policy · Privacy Policy.

Chat now
Call Sales
+34 614 443 757

More ways to contact us

¿Hablamos directamente?

Reserva una cita en mi agenda — yo te llamo o nos vemos por Google Meet

  • ✓Confirmación instantánea por WhatsApp
  • ✓Disponibilidad en tiempo real
  • ✓Recordatorio 1h antes
  • ✓Cancela o cambia hora con un click
Initial consultation · 30min
📅 Ver disponibilidad y reservar