Poly A.I CyberSecurity Scoring
Poly
Company Information
Website:https://www.poly.com
Employees number:2,986
Number of followers:188,434
NAICS:517
Industry Type:Telecommunications
Homepage:poly.com
Poly Risk Score (AI oriented)
Between 750 and 799
PolyTelecommunications
Updated:
02/06/2026
02/06/2026
765/1000
Fair
Baa
Poly Global Score (TPRM)
xxxx
PolyTelecommunications
Score locked

PolyFair
Current Score
765Baa (FAIR)
01000
1 incidents
-3 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
766
JULY 2026
766
JUNE 2026
768
Vulnerability
02 Jun 2026 • Poly
HP: Critical Vulnerability in HP VoIP Phones Enables Enterprise Network Breaches
Critical RCE Vulnerability in HP Poly VoIP Phones Exposes Enterprise Networks
765
CRITICAL-3
HPP1780411927
Critical RCE Vulnerability in HP Poly VoIP Phones Exposes Enterprise Networks
Security researchers at Rapid7 have disclosed a critical-severity vulnerability (CVE-2026-0826, CVSS 9.2) in multiple HP Poly Voice VoIP phone models, enabling remote code execution (RCE) with root privileges. The flaw, a stack-based buffer overflow in the parsing of Session Description Protocol (SDP) attributes, affects devices with Interactive Connectivity Establishment (ICE) enabled.
The vulnerability stems from an unchecked string copy in the candidate attribute parsing function, allowing attackers to trigger a buffer overflow by sending a maliciously crafted SIP INVITE request. Exploitation grants control over the program counter, registers, and stack data, bypassing ASLR and NX mitigations via Return Oriented Programming (ROP) chains. Successful attacks could lead to arbitrary code execution, providing a persistent foothold in enterprise networks.
Affected models include HP VVX series (VVX 150, 250, 350, 450) and Trio IP Conference series (Trio 8800, 8500, 8300) VoIP phones. Patches are available, and disabling ICE connectivity serves as a temporary mitigation.
Rapid7’s Douglas McKee highlights the broader risk: these devices, often deployed in trusted environments like conference rooms and executive offices, lack endpoint protection and can be leveraged for eavesdropping, lateral movement, or harvesting sensitive audio for vishing, deepfake attacks, or fraud. The vulnerability underscores the threat posed by unsecured networked devices in high-value corporate settings.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
MAY 2026
768
APRIL 2026
768
MARCH 2026
768
FEBRUARY 2026
768
JANUARY 2026
768
DECEMBER 2025
768
NOVEMBER 2025
768
OCTOBER 2025
768
SEPTEMBER 2025
768
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Poly ??
What was Poly's A.I Rankiteo Cyber Score in July 2026 ??
What was Poly's A.I Rankiteo Cyber Score in June 2026 ??
What was Poly's A.I Rankiteo Cyber Score in May 2026 ??
What was Poly's A.I Rankiteo Cyber Score in April 2026 ??
What was Poly's A.I Rankiteo Cyber Score in March 2026 ??
What was Poly's A.I Rankiteo Cyber Score in February 2026 ??
What was Poly's A.I Rankiteo Cyber Score in January 2026 ??
What was Poly's A.I Rankiteo Cyber Score in December 2025 ??
What was Poly's A.I Rankiteo Cyber Score in November 2025 ??
What was Poly's A.I Rankiteo Cyber Score in October 2025 ??
What was Poly's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Poly's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Poly ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Poly's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?