vulnerability
HP Polycom: CVE-2026-0826: UC Software Stack-Based Buffer Overflow Vulnerability
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 10 | (AV:N/AC:L/Au:N/C:C/I:C/A:C) | Jun 2, 2026 | Jun 2, 2026 | Jun 2, 2026 |
Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
Jun 2, 2026
Added
Jun 2, 2026
Modified
Jun 2, 2026
Description
A critical unauthenticated stack-based buffer overflow vulnerability exists within the core session-handling binary (polyapp) of HP Poly UC Software. The flaw allows a remote, unauthenticated attacker to overflow an internal memory stack buffer by transmitting a specially crafted packet to the device over the network. Successful exploitation grants the attacker full arbitrary code execution with root administrative privileges on the underlying operating system pipeline of the physical asset.
Solution
hp-poly-mitigation-cve-2026-0826
References
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.