AI just turned quietly sitting bugs into public ammunition, and the vendors who ship those products are already losing.
Researchers pointed coding agents at old papers, public datasets, and forgotten admin surfaces and got working results. Dark Reading describes a flood of reports that product teams cannot triage, disclose, or patch at human speed. That flood is now everyday cybersecurity work, whether your scanner, your VAR, or a random gist delivers it first.
Sangoma Switchvox is the production proof.
CVE-2026-9586 is an unauthenticated SQL injection that remote attackers can walk straight to code execution. SecurityWeek reports active exploitation. If that box still answers on the public internet, treat it as hostile until you prove otherwise.

Vendors drowned in their own findings
Secure-by-design was supposed to mean fewer surprises. What you are watching instead is a disclosure bottleneck with a body count. AI-assisted hunting collapsed the cost of finding yesterday’s mistakes, so every mid-market appliance, every forgotten PHP panel, every “internal” admin UI is getting a second look from people who do not work for the vendor.
Cloudflare is pitching production traffic and WAF signals as a way to rank what to fix first, even drafting edge mitigations and patch suggestions. Fine. That is one vendor trying to industrialize triage. Your environment still has to survive the weeks when the actual product owner is still arguing about severity.
Attackers skipped the argument. They do not need a brute-force campaign against a login form when a single unauthenticated query hands them the box. They also do not need a CVE at all. Researchers this week found a Linux implant called ted compiled directly into HAProxy builds at two South Korean organizations, intercepting web traffic and rewriting pages for chosen visitors. That is not a HAProxy bug. Someone already had code execution, then made the load balancer the persistence layer.

This is a bad look for any shop that still files the phone system under facilities and the load balancer under “the network team’s problem.”
Cybersecurity still schedules around vendor time
Most cyber security programs still run on a 2019 clock. Wait for the advisory. Wait for the PSA. Wait for change freeze to lift. Meanwhile the exploit is already in packet captures you are not looking at.
The real problem here is scarcity thinking. You staffed threat detection, patch windows, and incident response for a world where serious bugs dripped out. AI flipped the volume. Your queue will keep growing even if every analyst works clean. Defense in depth has to assume the vendor is late, because they will be.
Stop treating the advisory as the start of the clock.
Internet-facing UC, VPN, and admin planes need the same threat-protection posture you already demand of mail and identity. A firewall in front of Switchvox that still forwards the vulnerable handler to the world is a router with opinions. Security hardening on the host matters only if the service cannot be reached unauthenticated from addresses you do not own.
Shrink exposure before the advisory ships
You cannot patch faster than a model can read a PDF. You can refuse to leave exploitable surface hanging on a public IP while the ticket ages.
Do this now, then keep doing it every week:
- Inventory the boring appliances. PBX, contact-center, jump hosts, load balancers, backup UIs. Record version, owner, management URL, and whether any of it is reachable from the WAN. If you cannot name the Switchvox build in production today, you are already late for CVE-2026-9586.
- Kill unauthenticated paths at the edge. Management interfaces belong on a dedicated admin network or a brokered jump, not on 443/tcp from the planet. Default-deny to the appliance; allow only known admin sources. If a vendor feature requires the world to speak SQL-shaped HTTP to the box, that feature stays off.
- Prove the binary, not the ticket. For HAProxy and anything else you compile or image yourself, pin sources, verify checksums, and compare running binaries against a known-good build. A clean CVE board does not detect extra objects linked into the proxy.
- Rehearse appliance RCE as identity loss. Incident response for a PBX or load-balancer shell should look like a tier-0 event: isolate, rotate creds and certs the box could see, hunt outbound beacons, and rebuild from a known image. Do not “reboot and monitor.”
Ongoing, put internet appliances on the same patch SLA as your domain controllers, with a 48-hour emergency track when a flaw is unauthenticated and remotely exploitable. Feed appliance logs into the same threat detection pipeline as everything else: SQL errors, unexpected admin sessions, config changes, and rebuilt packages. When a researcher publishes and your vendor is still “investigating,” ship a compensating control the same day: block the path, disable the module, or take the service off the WAN.
Hope is not a compensating control.
AI did you a favor and a disservice in the same week. The favor is visibility. The disservice is that every unpatched, internet-reachable product is now easier to find, easier to explain, and easier to own. Build the program around that volume, or keep discovering production shells in the same place you kept discovering them before: after someone else’s scanner got there first.
Sources
- AI Is Ending the Era of Hidden Vulnerabilities — Are Vendors Ready?
- Sangoma Switchvox Vulnerabilities Exploited in the Wild
- Introducing context-aware vulnerability discovery and remediation with Cloudflare Managed Defense and OpenAI Daybreak models
- New Ted Backdoor Hides Inside Victims’ Own HAProxy Builds to Intercept Web Traffic
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
