CYBER_THREATCAST
$ briefing --date=
CYBER THREATCAST
CYBER THREAT INTELLIGENCE BRIEFING
Threat actors are actively exploiting CVE-2026-9586, a critical unauthenticated SQL-injection flaw in Sangoma Switchvox. CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog, confirming that the risk has moved beyond disclosure into observed attacks.
Horizon3 reported exploitation and published indicators of compromise, giving organizations a concrete basis to examine Switchvox systems for intrusion. The combination of unauthenticated access, critical severity and in-the-wild abuse warrants immediate assessment of affected deployments.
Editorial: Recommended Actions
01
PRIORITY
Prioritize remediation of CVE-2026-9586 on Sangoma Switchvox and use Horizon3’s indicators of compromise to investigate affected systems. Threat actors are actively exploiting this critical unauthenticated SQL-injection vulnerability, and CISA has added it to the Known Exploited Vulnerabilities catalog.
02
PRIORITY
Update Google Chrome to 152.0.7977.82 or 152.0.7977.83 and Brave Desktop to 1.94.121, then relaunch the browsers to apply the fixes. Attackers are exploiting CVE-2026-85046, a V8 type-confusion flaw that crafted HTML can trigger to execute code within Chrome’s sandbox.
03
PRIORITY
Assess Citrix NetScaler ADC and NetScaler Gateway deployments for CVE-2026-19490 and upgrade affected systems immediately. The critical flaw permits remote authentication bypass under affected configurations, and exploit-like requests have already been observed from three IP addresses.
04
PRIORITY
Update Apple iOS to 18.4.1 or later, particularly for Serbian activists, civil-society members, and political opposition members. Apple neutralized the zero-click iMessage exploit used to deploy NSO Group’s Pegasus against at least 14 Serbian targets.
05
PRIORITY
Upgrade VMware Workstation and VMware Fusion 25H2 or 26H1 installations to 26H1u1. CVE-2026-59346 and CVE-2026-59347 can enable host-context code execution through VM-escape flaws, and Broadcom provides no workarounds.
ROUNDTABLE
Expert Panel Discussion
13 AI experts analyzed this briefing across 4 turns of structured debate
13Agents20Messages20mDuration
→
Field Signals
Real-time intelligence from X/Twitter
$ scanning feeds_