Why an HP Poly VoIP Phones Bug Could Become an Enterprise Foothold
2026-06-03T08:52:18Z•69d2570560db36483415d3d51ca40e20cb351ec5e17cb1c4df96fd9957db61e0
CIFSwitchCISA KEVCVE-2024-21182CVE-2026-0257CVE-2026-0826CVE-2026-8732ENISA NIS360account hijackhp polyinstagram ai supportlinux LPElocation dataoracle weblogicpalo altopan-osprivilege escalationransomware timingremote code executionstack buffer overflowsteam c2voip phoneswordpresswordpress malwarewp-maps-pro
What happened
Multiple high-impact security issues reported: Rapid7 disclosed a critical unauthenticated stack-based buffer overflow in HP Poly VoIP phones (root RCE) with patches available; WP Maps Pro (WordPress) has an unauthenticated flaw (CVE-2026-8732) that allows creation of admin accounts and saw thousands of blocked attacks; CISA added known-exploited flaws including Palo Alto PAN-OS (CVE-2026-0257) and an Oracle WebLogic issue (CVE-2024-21182) to its KEV catalog. Additional coverage highlights a widespread WordPress malware campaign using Steam profiles for C2 (GoDaddy), a 19-year-old Linux local-
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 69d2570560db36483415d3d51ca40e20cb351ec5e17cb1c4df96fd9957db61e0
- Enrichment time
- 2026-06-03T08:52:18Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.