Skip to main content

CVE detail

CVE-2026-0826

In certain scenarios when the admin has enabled Interactive Connectivity Establishment (ICE), a buffer overflow could enable remote code execution on Poly Voice products on the Linux platform.

CVSS 9.2 · CriticalBuzz score 37.5

Buzz score

Why this CVE is surfacing

Buzz score total 37.5

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 19.5 · diversity 18.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Mention score
19.5
6 evidence mentions in the snapshot
Diversity score
18.0
5 sources across 3 categories
KEV score
0.0
No KEV entry observed
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
1
within the 30d window
Peak daily
1
highest bucket

Evidence

Source links by recency

Newest mentions first
6 source links · newest first
  • Service in 2026: How the Underground Market Is Operationalizing Cybercrime Jeremy Makowski Vulnerabilities and Exploits CVE-2026-0826: How an Old Bug Can Feed AI-Powered Impersonation Douglas McKee, Director, Vulnerability Intelligence Vulnerabilities and Exploits CVE-2026-0826: Critical unauthenticated stack buffer overflow in HP Poly VVX and Trio Vo

    vendorwww.rapid7.comJul 16, 2026, 1:00 PM
  • A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. U.S. CISA adds SolarWinds Serv-U flaw to its Known Exploited Vulnerabilities catalog Report: Anthropic Deploys Engineers […]

    newssecurityaffairs.comJun 7, 2026, 2:39 PM
  • Rapid7 details a critical unauthenticated overflow in HP Poly VoIP phones that can lead to root RCE, with patches available for affected models. Rapid7’s latest disclosure on CVE-2026-0826 should get serious attention from anyone running HP Poly VoIP phones in an enterprise setting. It’s a critical unauthenticated stack-based buffer overflow that can give a remote […]

    newssecurityaffairs.comJun 3, 2026, 5:03 AM
  • HP has released patches for a critical buffer overflow vulnerability in multiple IP-enabled conference phones from its Poly Voice line. The flaw allows unauthenticated attackers to obtain root privileges on the underlying operating system, potentially enabling them to execute other attacks such as eavesdropping on conversations and recording voice data for AI-enabled impersonation attacks. The […]

    newswww.csoonline.comJun 2, 2026, 8:58 PM
  • A stack-based buffer overflow bug can be exploited for remote code execution on a vulnerable device.

    newswww.securityweek.comJun 2, 2026, 12:25 PM
  • No excerpt available.

    Vendor Advisorysupport.hp.comJun 1, 2026, 3:16 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence
  • CVE-2026-50039

    The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to cause a memory corruption via a Read Request.

    CVSS 8.7 · High
    1 mention
  • CVE-2026-64831

    FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and…

    CVSS 8.7 · High
    3 mentions
  • CVE-2026-61391

    There is a stack-based buffer overflow vulnerability in some Hikvision cameras, which may allow authenticated attackers to cause device malfunction by sending specially crafted pa…

    CVSS 7.2 · High
    1 mention
  • CVE-2026-16418

    Stack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium securi…

    CVSS N/A · Unrated
    2 mentions
  • CVE-2026-59144

    Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalidated elem_size in ring_read_seq. The attach-time validator ring_validate_header…

    CVSS 9.8 · Critical
    2 mentions
  • CVE-2026-16461

    A stack-based buffer overflow was found in rpcbind's rpcinfo utility. In rpcbdump() short mode (used by `rpcinfo -s`), version numbers from a remote RPCBPROC_DUMP reply are writte…

    CVSS 6.5 · Medium
    2 mentions