IoT, Vulnerability Management, Patch/Configuration Management

Zoom addresses critical remote code execution vulnerability

Today’s columnist, Andreas Brix of GlobalSign, writes that even Zoom plans on offering its own Zoom Mail Service for SMBs, so he doesn’t expect email to leave the business scene anytime soon. (Photo by Justin Sullivan/Getty Images)

As detailed in Security Affairs, Zoom has released critical security updates to address a severe vulnerability, identified as CVE-2026-22844, which poses a significant risk of remote code execution.

The command injection vulnerability was discovered by Zoom's Offensive Security team within Zoom Node Multimedia Routers (MMRs) prior to version 5.2.1716.0. This flaw, with a critical CVSS score of 9.9, could allow a meeting participant to execute arbitrary code on the MMR through network access. The vulnerability specifically impacts Node Meeting Connector (MC) MMR and Node Meetings Hybrid (ZMH) MMR modules.

While Zoom is not aware of any active exploitation in the wild, the company strongly advises administrators of affected deployments to update their MMR versions immediately.

Source: Security Affairs

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds