


Perceptive Security
SOC/SIEM Consultancy

A Command Injection vulnerability in Zoom Node Multimedia Routers (MMRs) before version 5.2.1716.0 may allow a meeting participant to conduct remote code execut…
Published:
19 januari 2026 om 23:00:00
Alert date:
20 januari 2026 om 15:01:54
Source:
nvd.nist.gov
Network Infrastructure, Enterprise Applications
A Command Injection vulnerability affects Zoom Node Multimedia Routers (MMRs) in versions before 5.2.1716.0. The vulnerability allows meeting participants to execute remote code on the MMR through network access. This represents a significant security risk as it enables unauthorized remote code execution by meeting participants. The vulnerability has been assigned CVE-2026-22844 and requires updating to version 5.2.1716.0 or later to remediate.
Technical details
Mitigation steps:
Affected products:
Zoom Node Multimedia Routers
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-22844
https://www.zoom.com/en/trust/security-bulletin/zsb-26001
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
