More locations: Toronto, ON, Canada
Sangoma provides secure, reliable business communications with a full suite of services including unified communications, networking, SIP trunking, wholesale voice, and security, offered in cloud, hybrid, or on-premises setups. Its core product is an in-house UC platform that enables voice, data, and connectivity across vertical industries, with options to bundle services. The company differentiates itself through ownership of the open-source Asterisk framework, a strong partner channel, and the Innovation Foundry that develops real-world solutions. Its goal is to be a single trusted source for comprehensive communications needs worldwide, serving over 100,000 customers across more than 180 countries.
Company Size
201-500
Company Stage
IPO
Headquarters
Markham, Canada
Founded
1984
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Health Insurance
Dental Insurance
Vision Insurance
Disability Insurance
Paid Vacation
Flexible Work Hours
Remote Work Options
Attackers exploit critical Switchvox flaw to deploy reverse shells without credentials. Ravie LakshmananSep 02, 2026 Vulnerability / Network Security Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution. The vulnerability in question is CVE-2026-9586 (CVSS score: 9.3), a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition 8.3 (104997) that can allow attackers to remotely execute arbitrary code as the PostgreSQL superuser without credentials. Sangoma released patches for the flaw in Switchvox 8.4.0.2 on July 14, 2026. "An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization," according to a description of the flaw on CVE.org. "An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution." Horizon3.ai said CVE-2026-9586 is among the 12 distinct vulnerabilities in Switchvox that were reported to Sangoma in April 2026, and that it is now seeing valid exploitation attempts in the wild against the flaw starting August 30, 2026. There are about 4,000 instances exposed to the internet, most of them located in the U.S. The same vulnerability was independently discovered and reported by Security Risk Advisors (SRA) Labs in May. "As an unauthenticated attacker, we were able to perform arbitrary database operations, including extracting database contents, modifying user records, and escalating privileges to Switchvox web administrators," SRA Labs said. "We also successfully executed arbitrary code on the server, invoking a reverse shell on the target machine." In one example highlighted by SRA Labs, successful exploitation of CVE-2026-9586 makes it possible to exfiltrate the cookie signing key to an external server, thereby allowing an attacker to forge authentication material for arbitrary users. The exploitation efforts targeting its honeypots involve the deployment of reverse shells on compromised systems, followed by running Base64-encoded commands to enumerate running processes. The autonomous penetration testing platform has shared the following indicators of compromise - * On devices that have SSH access enabled, evidence of the SQL injection payload used can be observed in "/var/log/switchvox/db-quirks.log" * Attacker IP address "176.65.148[.]184" It's worth noting that the IP address has been flagged on VirusTotal for conducting port scanning, brute-force, and exploitation efforts. "Given the quick succession of exploit attempts across multiple honeypots from the same source IP, we believe that it is likely that most internet exposed Switchvox instances will be or have already been targeted," security researcher Zach Hanley said. Found this article interesting? Follow Iniaes LLC. on Google News, Twitter and LinkedIn to read more exclusive content Iniaes LLC. post.
Sangoma and Jazzware partner to improve hotel operations and guest experience with integrated hospitality communications solution. TORONTO - Sangoma Technologies Corporation (TSX: STC; Nasdaq: SANG) ("Sangoma" or the "Company"), a trusted industry leader uniquely offering businesses a choice of on-premises, cloud-based, or hybrid Communications as a Service solutions, announced today a new integration between Sangoma UC for Hospitality and Jazzware, a leading provider of hospitality communications and guest experience software, serving...
Sangoma Technologies missed analyst expectations in its latest quarterly results, reporting revenues of US$51 million (2.1% below forecasts) and a statutory loss of US$0.07 per share, significantly worse than predicted. Following the earnings report, the six analysts covering the company have revised their forecasts. They now expect 2027 revenues of US$210.7 million, down from a previous consensus of US$217.4 million, representing a 0.7% annual decline. Per-share losses are projected to narrow 54% to US$0.09. The average price target fell 11% to CA$9.81, with estimates ranging from CA$8.02 to CA$11.04. This outlook contrasts sharply with the industry, where companies are expected to grow revenues by 7.1% annually, and marks a reversal from Sangoma's historical five-year growth rate of 7.2%.
Sangoma Technologies has reported third quarter fiscal 2026 results with revenue of $51 million, down less than 1% from the previous quarter. Excluding revenue from the sold VoIP Supply business, revenue declined less than 2% year-over-year on a like-for-like basis. The company saw strong performance in its MSP and Voice Infrastructure segments, growing 9% and 17% respectively. Adjusted EBITDA reached $7.5 million, representing 15% of revenue, whilst net loss was $2.3 million. Sangoma's board has engaged ATB Cormark Capital Markets to evaluate strategic alternatives following expressions of interest. The company has revised its fiscal 2026 guidance to revenue of $204–$205 million and Adjusted EBITDA margin of 15–16%, citing shifts in revenue timing, product mix and macroeconomic conditions. Total debt decreased approximately 39% year-over-year to $32.5 million.
Sangoma Technologies has reported second quarter fiscal 2026 results, with revenue of $51.5 million, up 1% sequentially. The Toronto-based communications solutions provider posted adjusted EBITDA of $8.3 million, representing 16% of revenue. The company generated $10.1 million in operating cash flow and $8.0 million in free cash flow during the quarter. Total debt decreased 38% year-over-year to $37.6 million, whilst cash stood at $17.1 million. Sangoma reported a 60% increase in monthly recurring revenue bookings year-over-year, with quarterly churn remaining below 1%. Gross profit margin improved to 74%, up from 72% in the previous quarter. The company has narrowed its full-year guidance to revenue of $205-208 million and adjusted EBITDA margin of 17-18%. More than 700,000 shares have been repurchased under its buyback programme launched in March 2025.