Critical Zoom Flaw (CVE-2026-22844): CVSS 9.9 Command Injection Exposes Hybrid Meetings
ID: 957d970b-9413-57f0-b23f-c8828f07da01
STIX ID: report--957d970b-9413-57f0-b23f-c8828f07da01
Feed Name: securityonline.info
Threat Score
### Executive Summary A critical Command Injection vulnerability (CVE-2026-22844, CVSS 9.9) has been disclosed in Zoom Node Multimedia Routers (MMR) affecting versions prior to 5.2.1716.0; a meeting participant can exploit the flaw via network access to achieve remote code execution on the MMR. Zoom advises administrators to urgently update MMRs to version 5.2.1716.0 or later to mitigate the risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
