KEV Intelligence is becoming Previdian.

Sangoma vendor intelligence

Sangoma Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting Sangoma products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Total KEVs
2
Known exploited vulnerabilities affecting Sangoma products
In CISA KEV
1
Records also listed in the official catalog
Beyond CISA KEV
1
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
0
Sangoma KEVs with sensor-observed exploitation activity

Review Sangoma exploitation against the products you run

Review exploited Sangoma vulnerabilities against the products you run. CISA KEV coverage is shown below.

50%
Covered by CISA
50%
Beyond CISA
2
Product families

Attested Sangoma vulnerabilities

2 known exploited vulnerabilities in this exploited-vulnerability portfolio. Search, then narrow it to official CISA coverage or the additional records Previdian tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2026-9586

Unauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMB

Switchvox SMB Edition High Beyond CISA 01 Sep 2026
CVE-2019-19006

Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.

FreePBX Confirmed In CISA 01 Jun 2026

Showing 2 of 2 Sangoma known exploited vulnerabilities.

Recurring weakness patterns

Authentication and neutralization account for two mapped occurrences across this Sangoma KEV portfolio.

Browse all KEVs →