Sangoma Switchvox Exploit: What SMBs Need to Know

A vulnerability in Sangoma's Switchvox phone system is being actively exploited by hackers to plant reverse shells on business networks. If your company uses Switchvox — or any internet-connected VoIP system — this is not a theoretical risk. Attackers are targeting real businesses right now, and the consequences range from data theft to full network compromise.

What Is the Sangoma Switchvox Exploit and Why Does It Matter?

Switchvox is a popular business phone system built on Asterisk, widely used by small and medium businesses that want a full-featured unified communications platform without enterprise price tags. The flaw being exploited allows attackers to send a specially crafted request to an exposed Switchvox interface and gain the ability to execute commands on the underlying server.

A reverse shell is what happens next. Instead of the attacker knocking on your door, the compromised system reaches out to theirs — making it much harder for standard firewalls to detect or block. Once that connection is established, the attacker effectively has a live terminal inside your network. From there, they can move laterally, steal credentials, deploy ransomware, or quietly exfiltrate data for weeks before anyone notices.

For SMBs, this matters more than you might think. Business phone systems sit at the centre of your operations, often connected to customer relationship management tools, billing platforms, and internal directories. Compromise one, and you may have handed attackers a skeleton key.

How Attackers Turn a Phone System Into a Foothold

VoIP systems are a favourite target precisely because they are often forgotten in routine security reviews. Servers get patched. Laptops get endpoint protection. But the phone system? It gets set up, it works, and nobody touches it again for years.

Attackers know this. They scan the internet continuously for exposed management interfaces — and Switchvox panels left accessible from the public internet are an easy find. Once they identify a vulnerable version, exploitation can be automated and fast. The reverse shell gives them persistent, hard-to-detect access, often using encrypted channels that blend in with normal traffic.

What makes this campaign particularly concerning is that credentials harvested from the compromised system frequently end up in infostealer logs and dark web dumps within days. Breachrr monitors those exact sources — infostealer marketplaces, breach databases, and dark web forums — so we often see stolen credentials surface before the victim organisation even knows they have been hit.

What SMBs Should Do Right Now

If you run Switchvox, the first step is straightforward: check your version and apply any available patches from Sangoma immediately. If your Switchvox administration interface is accessible directly from the public internet, restrict it to specific IP addresses or move it behind a VPN. There is no good reason that management panel needs to be exposed to the entire world.

Beyond patching, look at your broader network segmentation. Your phone system should not have unrestricted access to your file servers, your CRM, or your finance tools. Segment your network so that even if one system is compromised, the blast radius is contained.

Also review which accounts have administrative access to Switchvox and ensure those credentials are not reused anywhere else. Credential reuse is consistently one of the top ways a single breach snowballs into a full organisational compromise. If your Switchvox admin password also unlocks your email or cloud storage, one attack can cascade into many.

The Broader Lesson for SMB Security in 2026

The Sangoma Switchvox exploit is a reminder that attackers do not always come through the front door. They probe the systems businesses overlook — VoIP platforms, legacy servers, forgotten admin panels — because those are where defences are weakest.

For small and medium businesses, staying ahead of this requires visibility. You need to know when your credentials appear in a breach dump, when your domain infrastructure is being probed, or when stolen data from your organisation surfaces on dark web markets. That is exactly what Breachrr is built to do.

If you are not sure what exposure your business already has, the best place to start is a free audit. Run yours at breachrr.com/audit and find out what attackers might already know about your organisation before they use it against you.

Want to see if your company is exposed?

Want to see if your company is exposed?

Run a free audit →
Sangoma Switchvox Exploit: What SMBs Need to Know · Breachrr · Breachrr