CVE-2026-0826: Critical unauthenticated stack buffer overflow in HP Poly VVX and Trio VoIP Phones (FIXED)

2026-06-03T07:23:45Zfe72f3b68011da4737527b06425183c4d8163889934ee28b759a7da271a3f6cf
CVE-2026-0826HPICEPolySDPTrioVVXVoIPmitigation:disable-ICEpatch availablerapid7remote code executionroot privilegestack buffer overflowunauthenticated RCE

What happened

Rapid7 Labs discovered CVE-2026-0826, a critical unauthenticated stack-based buffer overflow in HP/Poly VoIP phones (VVX series: VVX 150/250/350/450 and three Trio models). The flaw is in parsing Session Description Protocol (SDP) attributes for Interactive Connectivity Establishment (ICE); when ICE is enabled (not enabled by default), a remote unauthenticated attacker can trigger a stack overflow to achieve remote code execution as root. Vendor has released fixes; mitigations include applying vendor patches urgently or disabling the ICE feature until patched.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
fe72f3b68011da4737527b06425183c4d8163889934ee28b759a7da271a3f6cf
Enrichment time
2026-06-03T07:23:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.