Rapid7 disclosed CVE-2026-0826, a critical unauthenticated stack-based buffer overflow in HP Poly VVX and Trio VoIP phones that can allow remote code execution as root. The flaw resides in SDP parsing of ICE candidate attributes within the polyapp binary when the non-default ICE feature is enabled. Rapid7 demonstrated exploitation against a Poly VVX 450 running firmware 6.4.7.4477, showing that existing mitigations were not sufficient in practice: NX was enabled, but the binary lacked PIE, and some shared libraries loaded at fixed addresses despite nominal ASLR, enabling a ROP-based exploit. HP said the issue affects all VVX models and several Trio conference phones, assigned it a CVSSv4 9.2, and released patched firmware while advising administrators to disable ICE if it is not required.
The disclosure also warned that compromised enterprise desk phones can become stealthy footholds for persistence, lateral movement, traffic interception, and call manipulation, while exposing sensitive audio from executive offices and conference rooms. Rapid7 said the risk extends beyond traditional espionage because control of trusted business phones could support AI-enabled impersonation, including vishing and deepfake-assisted fraud, underscoring that VoIP endpoints should be treated as fully networked computers rather than benign office appliances.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
HP confirmed that all VVX models and several Trio conference phone models are affected by CVE-2026-0826, assigned it a CVSS v4 score of 9.2, and released patched firmware versions. HP also recommended disabling ICE where it is not needed.
Rapid7 disclosed CVE-2026-0826, a critical unauthenticated stack-based buffer overflow affecting HP Poly VVX and Trio VoIP devices that can enable remote code execution. The flaw is in SDP parsing of ICE candidate attributes in the polyapp binary when the non-default ICE feature is enabled.
Cisco’s AI threat intelligence team reported that single-turn safety benchmarks understate real-world risk and that all 15 tested closed frontier models failed a meaningful share of adaptive multi-turn attacks. The study found attack success rates rose sharply in multi-turn testing and that deployment configuration choices, such as reasoning mode, could materially change outcomes.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
thenewstack.io
Open sourcerapid7.com
Open sourcerapid7.com
Open sourcehelpnetsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.