CVE-2026-0826: How an Old Bug Can Feed AI-Powered Impersonation

2026-06-02T07:23:49Zdcdcbc03fb3850f30da2ba57947a76932eb157b063d2dda6e22ead8d563ebed1
CVE-2026-0826HP PolyICERCESDPTrioVVXVoIPattack surfacepatch availablerootstack-based buffer overflowunauthenticatedvoice-impersonation risk

What happened

Rapid7 Labs discovered and responsibly disclosed CVE-2026-0826: a critical, unauthenticated stack-based buffer overflow in HP/Poly VoIP devices that can lead to remote code execution as root. The bug exists in SDP attribute parsing for ICE (Interactive Connectivity Establishment); ICE must be enabled (it is off by default) for remote exploitation. Rapid7 validated the issue on a VVX 450 and confirmed it affects the VVX series (VVX 150/250/350/450) and multiple Trio IP Conference models (e.g., Trio 8800 and 8500). Vendor updates are available (vulnerability marked FIXED). Because these are desk

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
dcdcbc03fb3850f30da2ba57947a76932eb157b063d2dda6e22ead8d563ebed1
Enrichment time
2026-06-02T07:23:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.