CVE-2026-0826: Critical unauthenticated stack buffer overflow in HP Poly VVX and Trio VoIP Phones (FIXED)

2026-06-02T19:23:49Z3293ea7f021243b2d64ae55a239b11b8149508a4294bbcc54a570752695f1d94
CVE-2026-0826HP PolyICERCESDPTrioVVXVoIPpatchrapid7remote-executionrootsecurity-advisorystack-buffer-overflowunauthenticatedvoice-infrastructure

What happened

Rapid7 Labs disclosed CVE-2026-0826, a critical unauthenticated stack-based buffer overflow in HP/Poly VVX (150/250/350/450) and multiple Trio VoIP phones. The flaw exists in parsing Session Description Protocol (SDP) ICE attributes; ICE must be enabled (not enabled by default) for remote exploitation. Successful exploitation yields unauthenticated remote code execution as root. Vendor advisories and fixes were published. The Rapid7 feed also contextualizes the risk to enterprise voice infrastructure and notes related incidents and advisories in the same timeframe (e.g., PAN-OS CVE-2026-0257,+

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
3293ea7f021243b2d64ae55a239b11b8149508a4294bbcc54a570752695f1d94
Enrichment time
2026-06-02T19:23:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · CVE-2026-0826: Critical unauthenticated stack buffer overflow in HP Poly VVX and Trio VoIP Phones (FIXED) · Baitaphish