logo

Critical Zoom Flaw (CVE-2026-22844): CVSS 9.9 Command Injection Exposes Hybrid Meetings

ID: 957d970b-9413-57f0-b23f-c8828f07da01

STIX ID: report--957d970b-9413-57f0-b23f-c8828f07da01

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-01-21

Date Updated: 2026-04-23

Author: Ddos

...
...

### Executive Summary A critical Command Injection vulnerability (CVE-2026-22844, CVSS 9.9) has been disclosed in Zoom Node Multimedia Routers (MMR) affecting versions prior to 5.2.1716.0; a meeting participant can exploit the flaw via network access to achieve remote code execution on the MMR. Zoom advises administrators to urgently update MMRs to version 5.2.1716.0 or later to mitigate the risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.