Why an HP Poly VoIP Phones Bug Could Become an Enterprise Foothold

2026-06-03T08:52:18Z69d2570560db36483415d3d51ca40e20cb351ec5e17cb1c4df96fd9957db61e0
CIFSwitchCISA KEVCVE-2024-21182CVE-2026-0257CVE-2026-0826CVE-2026-8732ENISA NIS360account hijackhp polyinstagram ai supportlinux LPElocation dataoracle weblogicpalo altopan-osprivilege escalationransomware timingremote code executionstack buffer overflowsteam c2voip phoneswordpresswordpress malwarewp-maps-pro

What happened

Multiple high-impact security issues reported: Rapid7 disclosed a critical unauthenticated stack-based buffer overflow in HP Poly VoIP phones (root RCE) with patches available; WP Maps Pro (WordPress) has an unauthenticated flaw (CVE-2026-8732) that allows creation of admin accounts and saw thousands of blocked attacks; CISA added known-exploited flaws including Palo Alto PAN-OS (CVE-2026-0257) and an Oracle WebLogic issue (CVE-2024-21182) to its KEV catalog. Additional coverage highlights a widespread WordPress malware campaign using Steam profiles for C2 (GoDaddy), a 19-year-old Linux local-

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
69d2570560db36483415d3d51ca40e20cb351ec5e17cb1c4df96fd9957db61e0
Enrichment time
2026-06-03T08:52:18Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Why an HP Poly VoIP Phones Bug Could Become an Enterprise Foothold · Baitaphish