Critical Zoom Command Injection Vulnerability Enables Remote Code Execution
A critical command injection vulnerability has been identified in Node Multimedia Routers (MMRs), potentially allowing meeting participants to execute arbitrary code on affected systems.
A critical command injection vulnerability has been identified in Node Multimedia Routers (MMRs), potentially allowing meeting participants to execute arbitrary code on affected systems.
The vulnerability, assigned CVE-2026-22844, has a CVSS severity rating of 9.9, indicating a significant threat that requires immediate attention.
The command injection flaw affects Zoom Node MMR versions prior to 5.2.1716.0 and impacts Zoom Node Meetings Hybrid (ZMH) and Zoom Node Meeting Connector (MC) environments. The vulnerability can be exploited through network access with low-level privileges and does not require user interaction.
CVE ID: CVE-2026-22844 Bulletin: ZSB-26001 CVSS Score: 9.9 (Critical) Attack Vector: Network Flaw Type: Command Injection
An attacker with valid meeting participant credentials could leverage the flaw to execute remote code on the MMR infrastructure. The vulnerability poses high risks to confidentiality, integrity, and availability, enabling potential data theft, system configuration modifications, and service disruptions.
The vulnerability, assigned CVE-2026-22844, has a CVSS severity rating of 9.9, indicating a significant threat that requires immediate attention.
Organizations using Zoom Node Meetings, Hybrid, or Meeting Connector deployments are advised to address this vulnerability urgently. The flaw specifically targets MMR modules running versions before 5.2.1716.0. Identifying and applying the necessary patches is the primary mitigation strategy. Zoom's Offensive Security team discovered the vulnerability.
Zoom recommends administrators update affected MMR modules to version 5.2.1716.0 or later. Detailed guidance is available in the Managing Updates for Zoom Node documentation, which includes step-by-step instructions for patch deployment.
Organizations should prioritize this update as critical, treating it with urgency similar to responses to zero-day vulnerabilities. Given the vulnerability's low attack complexity and basic participant-level access requirements, there is a substantial risk of exploitation in real-world scenarios.
Immediate verification of current MMR versions and prompt patch deployment is strongly advised.
The critical severity rating and ease of exploitation underscore the significant security risk this vulnerability presents, requiring urgent attention in all affected environments.
Based on reporting by Cyber Security News.
