{"id":1368,"date":"2026-09-03T11:50:39","date_gmt":"2026-09-03T06:20:39","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1368"},"modified":"2026-09-04T10:35:11","modified_gmt":"2026-09-04T05:05:11","slug":"sangoma-switchvox-attack-cve-2026-9586","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/sangoma-switchvox-attack-cve-2026-9586\/","title":{"rendered":"Sangoma Switchvox Attack Exploits CVE-2026-9586 to Attempt Reverse Shells"},"content":{"rendered":"<p>A Sangoma Switchvox attack is actively exploiting CVE-2026-9586, a critical unauthenticated SQL injection vulnerability in Switchvox SMB Edition. The flaw can allow a remote attacker to reach operating-system command execution.<\/p>\n<p>The vulnerability affects the unauthenticated <code>\/pa<\/code> HTTP endpoint. Horizon3 observed valid exploitation attempts on August 30, 2026. The observed payload attempted to establish a reverse shell before collecting information about running processes.<\/p>\n<p>Sangoma addressed the vulnerability in Switchvox 8.4.0.2, released on July 14, 2026. Therefore, organizations running affected Switchvox installations should prioritize the update. They should also investigate systems exposed before patching for evidence of exploitation.<\/p>\n<h2>Sangoma Switchvox CVE-2026-9586 at a glance<\/h2>\n<table style=\"font-weight: 400; width: 100.648%;\" data-tablestyle=\"MsoTableGrid\" data-tablelook=\"1696\" aria-rowcount=\"12\" aria-colcount=\"2\">\n<tbody>\n<tr aria-rowindex=\"1\">\n<td style=\"width: 30.5433%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Detail<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 107.783%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Information<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"2\">\n<td style=\"width: 30.5433%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">CVE<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 107.783%;\" data-celllook=\"0\"><span data-contrast=\"auto\">CVE-2026-9586<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"3\">\n<td style=\"width: 30.5433%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Product<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 107.783%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Sangoma Switchvox SMB Edition<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"4\">\n<td style=\"width: 30.5433%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Vulnerability type<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 107.783%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Unauthenticated SQL injection leading to remote code execution<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"5\">\n<td style=\"width: 30.5433%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">CWE<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 107.783%;\" data-celllook=\"0\"><span data-contrast=\"auto\">CWE-89<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"6\">\n<td style=\"width: 30.5433%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">CVSS<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 107.783%;\" data-celllook=\"0\"><span data-contrast=\"auto\">CVSS v4.0: 9.3, Critical<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"7\">\n<td style=\"width: 30.5433%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Attack vector<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 107.783%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Network<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"8\">\n<td style=\"width: 30.5433%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Authentication required<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 107.783%;\" data-celllook=\"0\"><span data-contrast=\"auto\">No<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"9\">\n<td style=\"width: 30.5433%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">User interaction<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 107.783%;\" data-celllook=\"0\"><span data-contrast=\"auto\">No<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"10\">\n<td style=\"width: 30.5433%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Exploitation status<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 107.783%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Active exploitation\u00a0observed\u00a0by Horizon3<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"11\">\n<td style=\"width: 30.5433%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Fixed version<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 107.783%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Switchvox 8.4.0.2<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"12\">\n<td style=\"width: 30.5433%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Patch release date<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 107.783%;\" data-celllook=\"0\"><span data-contrast=\"auto\">July 14, 2026<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>What Is CVE-2026-9586 in Sangoma Switchvox?<\/h2>\n<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2026-9586?utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=sangoma_switchvox_attack\" target=\"_blank\" rel=\"nofollow noreferrer noopener\">CVE-2026-9586<\/a> is an unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition. It affects the <code>\/pa<\/code> HTTP endpoint and can allow a remote attacker to execute operating-system commands through crafted XML input.<\/p>\n<p>The vulnerability is particularly significant because exploitation requires neither authentication nor user interaction. As a result, vulnerable Switchvox systems reachable from untrusted networks can face remote exploitation attempts.<\/p>\n<h2>How the Switchvox \/pa Endpoint Turns SQL Injection Into RCE<\/h2>\n<p>The distinctive mechanism behind the Sangoma Switchvox attack starts with an unauthenticated XML request reaching the underlying PostgreSQL database.<\/p>\n<p>Switchvox exposes an unauthenticated <code>\/pa<\/code> HTTP endpoint for functionality associated with supported phones. Horizon3 traced requests to this endpoint through the <code>PhoneAppsHandler.pm<\/code> handler.<\/p>\n<p>The vulnerable processing flow works as follows:<\/p>\n<ol>\n<li>The <code>\/pa<\/code> endpoint receives the HTTP request body.<\/li>\n<li>Switchvox verifies that the body begins with <code>&lt;PolycomIPPhone&gt;<\/code>.<\/li>\n<li>The application parses the supplied XML.<\/li>\n<li>It extracts the attacker-controlled <code>PhoneIP<\/code> value.<\/li>\n<li>The application concatenates that value directly into an SQL query without parameterization.<\/li>\n<li>The resulting query executes against PostgreSQL.<\/li>\n<\/ol>\n<p>Critically, Horizon3 reported that the database query executes as a PostgreSQL superuser.<\/p>\n<p>As a result, exploitation can move beyond database manipulation. A crafted query can use PostgreSQL functionality to execute commands on the underlying operating system.<\/p>\n<p>Therefore, CVE-2026-9586 is not simply a database confidentiality issue. An unauthenticated network request can cross the database boundary and reach operating-system command execution.<\/p>\n<h2>Attackers Are Exploiting CVE-2026-9586 Against Switchvox Honeypots<\/h2>\n<p>The Switchvox vulnerability is no longer only a proof-of-concept risk.<\/p>\n<p>Horizon3 and Defused Cyber deployed internet-facing Switchvox honeypots in May 2026 to watch for exploitation. On August 30, 2026, those systems recorded valid exploitation attempts.<\/p>\n<p>The activity originated from 176.65.148.184.<\/p>\n<p>The first observed payload used Netcat to connect to 176.65.148.184 on port 39323 and piped data from that connection into <code>sh<\/code>, providing a mechanism for remote command execution.<\/p>\n<p>Next, a command gathered information about running processes. It decoded a <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-base64\/\">Base64<\/a>-encoded shell instruction and extracted information about the top process. Then, it used <code>curl<\/code> to send the resulting information to a remote server.<\/p>\n<p>Horizon3 reported that the same source rapidly targeted multiple honeypots.<\/p>\n<p>However, the available research does not establish broader post-exploitation activity such as credential theft, persistence or lateral movement. These remain possible consequences of server compromise, not confirmed outcomes of the observed activity.<\/p>\n<h2>Why Internet-Exposed Switchvox Systems Face Higher Exploitation Risk<\/h2>\n<p>The Switchvox exploit requires no authenticated account or user interaction.<\/p>\n<p>Therefore, vulnerable installations reachable from untrusted networks are particularly important to identify. An attacker capable of reaching the vulnerable HTTP endpoint can attempt exploitation remotely.<\/p>\n<p>Horizon3 reported approximately 4,000 internet-visible Switchvox devices in Shodan when it published its research. In addition, the researchers observed rapid targeting across multiple honeypots. They said this activity suggested widespread scanning or exploitation attempts against exposed systems.<\/p>\n<p>For enterprise VoIP security, this exposure deserves attention because Switchvox can form part of business-critical communications infrastructure. Successful exploitation can provide command execution within an environment connected to corporate networks.<\/p>\n<p>However, the confirmed activity does not establish that attackers moved from Switchvox into adjacent systems. Organizations should investigate exposed systems rather than assume that patching removes evidence of an earlier compromise.<\/p>\n<h2>How to Check Switchvox for CVE-2026-9586 Exploitation<\/h2>\n<p>Organizations running vulnerable Switchvox installations should first determine whether their systems were accessible from untrusted networks.<\/p>\n<p>Where administrators have <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-secure-shell-ssh\/\">SSH<\/a> access, Horizon3 recommends inspecting:<\/p>\n<p><code>\/var\/log\/switchvox\/db-quirks.log<\/code><\/p>\n<p>The log can contain evidence of SQL statements associated with exploitation attempts.<\/p>\n<p>In addition, security teams should review available network telemetry for:<\/p>\n<ul>\n<li>176.65.148.184<\/li>\n<li>TCP port 39323<\/li>\n<li>Unexpected outbound connections from Switchvox systems<\/li>\n<li>Unusual <code>curl<\/code> activity associated with the appliance<\/li>\n<li>Unexpected Netcat-related activity<\/li>\n<\/ul>\n<p>The IP address is an indicator from the activity Horizon3 observed. However, its absence does not prove that another source did not target the system.<\/p>\n<p>Finally, teams should preserve relevant logs before remediation when they suspect compromise.<\/p>\n<h2>Patch Switchvox to Version 8.4.0.2 or Later<\/h2>\n<p>Immediately upgrade affected Switchvox installations to version 8.4.0.2 or later to remediate CVE-2026-9586.<\/p>\n<p>Sangoma released Switchvox 8.4.0.2 on July 14, 2026, with CVE-2026-9586 listed among the resolved security issues. Because public sources differ on the scope of earlier affected versions, organizations running older Switchvox releases should upgrade rather than assume they are unaffected.<\/p>\n<p>Administrators should also reduce unnecessary external exposure to Switchvox services.<\/p>\n<p>Patching closes the vulnerable code path. However, an update cannot establish whether exploitation occurred before remediation. Therefore, organizations with previously exposed systems should also review relevant logs and network activity.<\/p>\n<h2>Where Hexnode Fits After a Sangoma Switchvox Attack<\/h2>\n<p>Hexnode does not replace the Switchvox update or directly remediate CVE-2026-9586. Its role is to strengthen and investigate supported endpoints surrounding the affected communications environment.<\/p>\n<h3>Investigate Downstream Windows and macOS Endpoint Activity with Hexnode XDR<\/h3>\n<p>If an investigation finds suspicious activity on Windows or macOS endpoints surrounding the affected communications environment, <a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a> can provide visibility to support further investigation.<\/p>\n<p>Security teams can use endpoint and threat context to investigate suspicious activity and understand whether signs of compromise extend beyond the Switchvox system. This helps teams assess activity on Windows and macOS environments while investigating the broader scope of an incident.<\/p>\n<p>Hexnode XDR does not detect or patch CVE-2026-9586 on the Switchvox appliance. Its role in this incident is to support investigation of suspicious activity on surrounding Windows and macOS endpoints if evidence suggests the attack extended beyond Switchvox.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Thumbnail-For-XDR-Intro-Deck-1.webp?format=webp\" class=\"resource-box__image\" alt=\"Thumbnail-For-XDR-Intro-Deck\" loading=\"lazy\" srcset=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Thumbnail-For-XDR-Intro-Deck-1.webp?format=webp 1796w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Thumbnail-For-XDR-Intro-Deck-1-300x168.webp?format=webp 300w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Thumbnail-For-XDR-Intro-Deck-1-1024x575.webp?format=webp 1024w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Thumbnail-For-XDR-Intro-Deck-1-768x431.webp?format=webp 768w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Thumbnail-For-XDR-Intro-Deck-1-1536x862.webp?format=webp 1536w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Thumbnail-For-XDR-Intro-Deck-1-178x100.webp?format=webp 178w\" sizes=\"auto, (max-width: 1796px) 100vw, 1796px\" title=\"Thumbnail-For-XDR-Intro-Deck\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Introduction to Hexnode XDR\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Learn how Hexnode XDR brings threat visibility, investigation, and endpoint response together to help security teams investigate suspicious activity and respond to endpoint threats.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/introduction-to-hexnode-xdr\/'>\n                            Download the Presentation\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h3>Keep VoIP Administration Endpoints Governed with Hexnode UEM<\/h3>\n<p>Administrator workstations are another relevant control point.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/uem\/\">Hexnode UEM<\/a> can apply device-management and compliance policies to supported endpoints used for administrative tasks. For example, organizations can maintain requirements around OS posture, encryption, password policies and application compliance.<\/p>\n<p>These controls do not prevent exploitation of the Switchvox <code>\/pa<\/code> endpoint. Instead, they strengthen the management endpoints administrators use to access enterprise infrastructure.<\/p>\n<p>Therefore, organizations should separate these responsibilities. Switchvox must be patched through Sangoma&#8217;s supported update process, while endpoint controls govern the systems surrounding its administration and investigation.<\/p>\n<h2>Enterprise Response Checklist for the Sangoma Switchvox Attack<\/h2>\n<p>Organizations using Sangoma Switchvox should treat CVE-2026-9586 as an active-exploitation issue rather than a theoretical vulnerability.<\/p>\n<p>Prioritize these steps:<\/p>\n<ul>\n<li><strong>Inventory exposed Switchvox systems.<\/strong> Identify affected installations and determine which were internet-accessible.<\/li>\n<li><strong>Patch vulnerable installations.<\/strong> Upgrade affected systems to Switchvox 8.4.0.2 or later.<\/li>\n<li><strong>Preserve relevant evidence.<\/strong> Retain available logs before making investigative changes where compromise is suspected.<\/li>\n<li><strong>Review Switchvox logs.<\/strong> Examine <code>db-quirks.log<\/code> for suspicious SQL activity and related artifacts.<\/li>\n<li><strong>Hunt for published indicators.<\/strong> Review available telemetry for the observed IP address, port and unexpected outbound connections.<\/li>\n<li><strong>Investigate command execution.<\/strong> Determine whether suspicious commands executed before the system was patched.<\/li>\n<li><strong>Examine connected endpoints when warranted.<\/strong> Investigate surrounding systems if evidence suggests activity extended beyond Switchvox.<\/li>\n<li><strong>Reduce unnecessary exposure.<\/strong> Restrict external access to Switchvox services where business requirements permit.<\/li>\n<\/ul>\n<p>This sequence separates immediate remediation from investigation. Patching addresses the vulnerable software, while incident-response activities help determine whether attackers exploited it earlier.<\/p>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/5-Ways-Hexnode-Strengthens-Your-Incident-Response-Plan-1024x535-1.webp?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>5 Ways Hexnode Strengthens Your Incident Response Plan<\/h4><p>Learn how endpoint telemetry, and endpoint management can strengthen enterprise incident-response workflows.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/5-ways-hexnode-strengthens-your-incident-response-plan\/\" aria-label=\"5 Ways Hexnode Strengthens Your Incident Response Plan\"><\/a><\/div><\/div><\/div>\n<h3>Closing the Switchvox \/pa Attack Path<\/h3>\n<p>The Sangoma Switchvox attack demonstrates how one attacker-controlled XML value can cross several security boundaries.<\/p>\n<p>An unauthenticated request reaches the <code>\/pa<\/code> endpoint. Switchvox then extracts the attacker-controlled <code>PhoneIP<\/code> value and inserts it into an unparameterized PostgreSQL query. As a result, the SQL injection can reach operating-system command execution.<\/p>\n<p>Attackers have already attempted to use this path to establish reverse shells and collect process information.<\/p>\n<p>Therefore, enterprises running Switchvox should prioritize version 8.4.0.2 or later. They should also review the published indicators and investigate vulnerable systems exposed before patching.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Strengthen the endpoints around critical infrastructure<\/h5><p>Manage supported enterprise endpoints, enforce security and compliance policies, and strengthen the systems administrators use to access critical infrastructure.<\/p><a href=\"https:\/\/www.hexnode.com\/xdr\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Start Your Free Trial<\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>A Sangoma Switchvox attack is actively exploiting CVE-2026-9586, a critical unauthenticated SQL injection vulnerability in&#8230;<\/p>\n","protected":false},"author":4,"featured_media":1378,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[20,21],"class_list":["post-1368","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-network-and-vpn","category-patch-management","product_category-extended-detection-and-response","tab_group-vulnerabilities"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Sangoma Switchvox Attack Exploits CVE-2026-9586 for RCE<\/title>\n<meta name=\"description\" content=\"Sangoma Switchvox attack exploits CVE-2026-9586 to attempt reverse shells. Learn how the SQL injection reaches RCE.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/sangoma-switchvox-attack-cve-2026-9586\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Sangoma Switchvox Attack Exploits CVE-2026-9586 for RCE\" \/>\n<meta property=\"og:description\" content=\"Sangoma Switchvox attack exploits CVE-2026-9586 to attempt reverse shells. Learn how the SQL injection reaches RCE.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/sangoma-switchvox-attack-cve-2026-9586\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-03T06:20:39+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-04T05:05:11+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Sangoma-Switchvox-Attack-Exploits-CVE-2026-9586-to-Attempt-Reverse-Shell.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"754\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Nora Blake\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Nora Blake\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/sangoma-switchvox-attack-cve-2026-9586\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/sangoma-switchvox-attack-cve-2026-9586\\\/\"},\"author\":{\"name\":\"Nora Blake\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\"},\"headline\":\"Sangoma Switchvox Attack Exploits CVE-2026-9586 to Attempt Reverse Shells\",\"datePublished\":\"2026-09-03T06:20:39+00:00\",\"dateModified\":\"2026-09-04T05:05:11+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/sangoma-switchvox-attack-cve-2026-9586\\\/\"},\"wordCount\":1368,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/sangoma-switchvox-attack-cve-2026-9586\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Sangoma-Switchvox-Attack-Exploits-CVE-2026-9586-to-Attempt-Reverse-Shell.jpeg?format=webp\",\"articleSection\":[\"Network and VPN\",\"Patch Management\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/sangoma-switchvox-attack-cve-2026-9586\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/sangoma-switchvox-attack-cve-2026-9586\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/sangoma-switchvox-attack-cve-2026-9586\\\/\",\"name\":\"Sangoma Switchvox Attack Exploits CVE-2026-9586 for RCE\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/sangoma-switchvox-attack-cve-2026-9586\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/sangoma-switchvox-attack-cve-2026-9586\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Sangoma-Switchvox-Attack-Exploits-CVE-2026-9586-to-Attempt-Reverse-Shell.jpeg?format=webp\",\"datePublished\":\"2026-09-03T06:20:39+00:00\",\"dateModified\":\"2026-09-04T05:05:11+00:00\",\"description\":\"Sangoma Switchvox attack exploits CVE-2026-9586 to attempt reverse shells. Learn how the SQL injection reaches RCE.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/sangoma-switchvox-attack-cve-2026-9586\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/sangoma-switchvox-attack-cve-2026-9586\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/sangoma-switchvox-attack-cve-2026-9586\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Sangoma-Switchvox-Attack-Exploits-CVE-2026-9586-to-Attempt-Reverse-Shell.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Sangoma-Switchvox-Attack-Exploits-CVE-2026-9586-to-Attempt-Reverse-Shell.jpeg?format=webp\",\"width\":1340,\"height\":754,\"caption\":\"Sangoma Switchvox Attack Exploits CVE-2026-9586 to Attempt Reverse Shell\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/sangoma-switchvox-attack-cve-2026-9586\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Sangoma Switchvox Attack Exploits CVE-2026-9586 to Attempt Reverse Shells\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\",\"name\":\"Nora Blake\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"caption\":\"Nora Blake\"},\"description\":\"I write at the intersection of technology, process, and people, focusing on explaining complex products with clarity. I break down tools, systems, and workflows without any noise, jargon, or the hype.\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/nora-blake\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Sangoma Switchvox Attack Exploits CVE-2026-9586 for RCE","description":"Sangoma Switchvox attack exploits CVE-2026-9586 to attempt reverse shells. Learn how the SQL injection reaches RCE.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/sangoma-switchvox-attack-cve-2026-9586\/","og_locale":"en_US","og_type":"article","og_title":"Sangoma Switchvox Attack Exploits CVE-2026-9586 for RCE","og_description":"Sangoma Switchvox attack exploits CVE-2026-9586 to attempt reverse shells. Learn how the SQL injection reaches RCE.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/sangoma-switchvox-attack-cve-2026-9586\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-09-03T06:20:39+00:00","article_modified_time":"2026-09-04T05:05:11+00:00","og_image":[{"width":1340,"height":754,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Sangoma-Switchvox-Attack-Exploits-CVE-2026-9586-to-Attempt-Reverse-Shell.jpeg?format=webp","type":"image\/jpeg"}],"author":"Nora Blake","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Nora Blake","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/sangoma-switchvox-attack-cve-2026-9586\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/sangoma-switchvox-attack-cve-2026-9586\/"},"author":{"name":"Nora Blake","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d"},"headline":"Sangoma Switchvox Attack Exploits CVE-2026-9586 to Attempt Reverse Shells","datePublished":"2026-09-03T06:20:39+00:00","dateModified":"2026-09-04T05:05:11+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/sangoma-switchvox-attack-cve-2026-9586\/"},"wordCount":1368,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/sangoma-switchvox-attack-cve-2026-9586\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Sangoma-Switchvox-Attack-Exploits-CVE-2026-9586-to-Attempt-Reverse-Shell.jpeg?format=webp","articleSection":["Network and VPN","Patch Management"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/sangoma-switchvox-attack-cve-2026-9586\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/sangoma-switchvox-attack-cve-2026-9586\/","url":"https:\/\/www.hexnode.com\/threat-watch\/sangoma-switchvox-attack-cve-2026-9586\/","name":"Sangoma Switchvox Attack Exploits CVE-2026-9586 for RCE","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/sangoma-switchvox-attack-cve-2026-9586\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/sangoma-switchvox-attack-cve-2026-9586\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Sangoma-Switchvox-Attack-Exploits-CVE-2026-9586-to-Attempt-Reverse-Shell.jpeg?format=webp","datePublished":"2026-09-03T06:20:39+00:00","dateModified":"2026-09-04T05:05:11+00:00","description":"Sangoma Switchvox attack exploits CVE-2026-9586 to attempt reverse shells. Learn how the SQL injection reaches RCE.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/sangoma-switchvox-attack-cve-2026-9586\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/sangoma-switchvox-attack-cve-2026-9586\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/sangoma-switchvox-attack-cve-2026-9586\/#primaryimage","url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Sangoma-Switchvox-Attack-Exploits-CVE-2026-9586-to-Attempt-Reverse-Shell.jpeg?format=webp","contentUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Sangoma-Switchvox-Attack-Exploits-CVE-2026-9586-to-Attempt-Reverse-Shell.jpeg?format=webp","width":1340,"height":754,"caption":"Sangoma Switchvox Attack Exploits CVE-2026-9586 to Attempt Reverse Shell"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/sangoma-switchvox-attack-cve-2026-9586\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"Sangoma Switchvox Attack Exploits CVE-2026-9586 to Attempt Reverse Shells"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d","name":"Nora Blake","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","caption":"Nora Blake"},"description":"I write at the intersection of technology, process, and people, focusing on explaining complex products with clarity. I break down tools, systems, and workflows without any noise, jargon, or the hype.","url":"https:\/\/www.hexnode.com\/threat-watch\/author\/nora-blake\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1368","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1368"}],"version-history":[{"count":2,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1368\/revisions"}],"predecessor-version":[{"id":1377,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1368\/revisions\/1377"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1378"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1368"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1368"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}