Rapid7

vulnerability

HP Polycom: CVE-2026-0826: UC Software Stack-Based Buffer Overflow Vulnerability

Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
Jun 2, 2026
Added
Jun 2, 2026
Modified
Jun 2, 2026

Description

A critical unauthenticated stack-based buffer overflow vulnerability exists within the core session-handling binary (polyapp) of HP Poly UC Software. The flaw allows a remote, unauthenticated attacker to overflow an internal memory stack buffer by transmitting a specially crafted packet to the device over the network. Successful exploitation grants the attacker full arbitrary code execution with root administrative privileges on the underlying operating system pipeline of the physical asset.

Solution

hp-poly-mitigation-cve-2026-0826
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.