HP disclosed CVE-2026-0826, a critical buffer overflow vulnerability in certain Poly Voice devices running on Linux that can lead to remote code execution and possible remote control of affected systems. The flaw carries a CVSS v4.0 score of 9.2 and is remotely exploitable with low attack complexity, no privileges, and no user interaction, but only in deployments where an administrator has enabled Interactive Connectivity Establishment (ICE).
According to HP bulletin HPSBPY04083, affected products include VVX, Trio 8300, Trio 8500, and Trio 8800 devices. HP urged customers to update to the latest UCS firmware through HP Poly Lens and advised disabling ICE connectivity where it is not needed. The issue was reported by Stephen Fewer of Rapid7 and is classified under CWE-121.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Public technical details and exploit code for CVE-2026-0826, including a Metasploit module, were released, providing deeper analysis of the ParseICECandidate buffer overflow and making exploitation easier. The reporting also noted ASLR weaknesses on affected devices that facilitate ROP-style exploitation.
On 2026-06-01, CVE-2026-0826 was recorded as affecting HP Poly Voice products, with the issue described as a buffer overflow that may lead to remote code execution in certain scenarios. The entry assigns CWE-121 and notes a CVSS v4.0 severity indicating network attackability and high impact.
On 2026-06-01, HP published security bulletin HPSBPY04083 Rev. 1 disclosing CVE-2026-0826, a critical buffer overflow vulnerability that can enable remote code execution on certain Linux-based Poly Voice devices when ICE is enabled. HP advised customers to update to the latest UCS firmware via HP Poly Lens and to disable ICE when not needed.
HP's bulletin credits Stephen Fewer of Rapid7 with reporting the vulnerability affecting certain Poly Voice devices. The references do not provide a specific date for when the report was made.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcesecurityaffairs.com
Open sourcecyber.gc.ca
Open sourcecvefeed.io
Open sourcesupport.hp.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.