CVE-2026-12855: Insyde Software INSYDEH2O

High severity, CVSS 8.2. EPSS: 0.1% chance of exploitation in the next 30 days.

Unvalidated memory boundary could result in arbitrary code execution. The vulnerability exists in the code developed specifically for HP projects.

Affected products

Published 2026-09-09. Last modified 2026-10-01.