Vulnerability record

CVE-2026-12855

Severity: HighExploitation: No known exploitation

Patch status

No official fix confirmed yet

Until a fix ships, follow the vendor's mitigations, limit exposure of affected systems, and watch this record for a patch.

Description

Unvalidated memory boundary could result in arbitrary code execution. The vulnerability exists in the code developed specifically for HP projects.

Source: NIST National Vulnerability Database. Official vulnerability data, reproduced as published.

Intelligence timeline

Developments from the last 30 days, newest first.

  1. CVSS scoredUpdate

    CVE-2026-12855 scored CVSS 8.2

    Basis: NIST National Vulnerability Database

  2. Disclosed

    VU#553437: InsydeH2O IHISI SMM is vulnerable to unsafe memory write operations

    Basis: CERT/CC Vulnerability Notes (CERT advisory)

Coverage

References

  • insyde.com https://www.insyde.com/security-pledge/sa-2026009/