Vendor

Sangoma

As of , 4 Sangoma vulnerabilities are on CISA's list of exploited vulnerabilities; 3 were added in 2026. Patch first: CVE-2026-9586.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2026-9586SQL InjectionSangoma SwitchvoxPatch nowForensic triage required by CISA0.19
2CVE-2025-64328OS Command InjectionSangoma FreePBXPatch this weekMetasploit module; EPSS 0.850.85
3CVE-2025-57819Authentication BypassSangoma FreePBXPatch this weekMetasploit module; EPSS 0.850.85
4CVE-2019-19006Improper AuthenticationSangoma FreePBXPatch this weekEPSS 0.560.56

Products

Added each year

1232025: 1120252026: 332026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20251
20263

Used in ransomware