CVE-2026-0826
CVE-2026-0826 is a critical buffer overflow vulnerability in Poly Voice products running Linux when Interactive Connectivity Establishment (ICE) is enabled. This flaw could allow attackers to execute arbitrary code remotely.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Users of Poly Voice products on Linux platforms with ICE enabled
Real-world impact
Remote code execution could compromise systems, leading to data theft, system takeover, or further attacks.
Why this severity
CVSS 9.2 (critical) due to high exploitability and potential for full system compromise.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources (CISA KEV not listed, no vendor patch referenced)
Timeline
- Jun 1, 2026 · Jun 1, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 22, 2026 · 13d agoAdvisory updatedThe NVD record was last revised.