VDB
CVE-2026-12855
CVE-2026-12855
PUBLISHED
CVSS 8.2 HIGH
Reported by Insyde · Published September 9, 2026
Unvalidated memory boundary could result in arbitrary code execution. The vulnerability exists in the code developed specifically for HP projects.
Risk Scores
CVSS 3.1
8.2
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Insyde Software | InsydeH2O | See in the Solution |
| Insyde Software | InsydeH2O | See in the Solution, See in the Solution |
Timeline
- Sep 9, 2026 EPSS Score
- Sep 9, 2026 Coalition ESS Score
- Sep 9, 2026 CVE Published
- Sep 24, 2026 EPSS Score
- Oct 1, 2026 CVE Updated