CVE-2026-5923: HP Inc Poly Ccx

Medium severity, CVSS 6.0. EPSS: 0.2% chance of exploitation in the next 30 days.

Malicious use of a stolen cookie might allow modifications to the contents of the IP phone’s webpage.

Affected products

  • HP Inc Poly Ccx: before 9.50 (fixed in 9.50)
  • HP Inc Poly Edge E: before 8.6.0 (fixed in 8.6.0)
  • HP Inc Poly Trio c60: before 9.5.0 (fixed in 9.5.0)

Published 2026-07-08. Last modified 2026-07-09.