logo

Poly VoIP Phone Vulnerability Revealed with Public Exploit Code Disclosed

ID: 0bbb7b63-2a30-502f-b0c8-02146db8d99a

STIX ID: report--0bbb7b63-2a30-502f-b0c8-02146db8d99a

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-06-05

Date Updated: 2026-06-05

Author: Do Son

...
...

**CVE-2026-0826:** A critical stack-based buffer overflow in Poly (HP) VoIP phones enables unauthenticated remote code execution and full administrative/root takeover; public exploit code and a Metasploit module have been released, and the vendor has published firmware updates (e.g., VVX -> UCS 6.4.8) and mitigation guidance — patch or disable the vulnerable feature immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.