CVE-2026-0826
massBuffer Overflow RCE in HP Poly Linux Voice Products When ICE Is Enabled
CVE-2026-0826 is a critical buffer overflow (CWE-121) in HP's Poly voice products that run on the Linux platform. It is reachable over the network without privileges or user interaction, but only in scenarios where the administrator has enabled Interactive Connectivity Establishment (ICE), and HP's CVSS 4.0 vector marks the attack as requiring those precise timing conditions. A successful exploit could let a remote attacker execute arbitrary code on the affected phone or voice device, with high impact on its confidentiality, integrity and availability, turning a compromised endpoint into a potential foothold inside the enterprise network. Organizations running HP/Poly Linux-based voice endpoints (including VoIP phones) with ICE enabled are affected; the available advisory data does not enumerate specific models, version ranges or fixed firmware releases. There is no public proof-of-concept and the flaw is not yet in CISA KEV, but EPSS assigns a 32.2% probability of exploitation within 30 days (98th percentile) and news coverage indicates defenders are being urged to patch promptly.
What to do: Inventory HP/Poly Linux-based voice endpoints and check each device's configuration for ICE being enabled; disable ICE where it is not required and avoid exposing SIP/management interfaces directly to the internet. Apply the fixed firmware from HP's official security advisory once released - HP is the assigning CNA, so monitor hp.com advisories, as the available data does not yet list specific patched version numbers.
| HP (Poly) Poly voice products running on the Linux platform (including enterprise VoIP phones) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In certain scenarios when the admin has enabled Interactive Connectivity Establishment (ICE), a buffer overflow could enable remote code execution on Poly Voice products on the Linux platform.
- Weakness
- CWE-121
- Vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X