CVE-2026-20119Patch

MEDIUMCVSS 7.5 · HIGH

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability in the text rendering subsystem of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of input received by an affected device. An attacker could exploit this vulnerability by getting the affected device to render crafted text, for example, a crafted meeting invitation. As indicated in the CVSS score, no user interaction is required, such as accepting the meeting invitation. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1287

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 3 signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-02-05); latest day: 2
  • 6 total mentions across 3 days

Deep dive

Activity timeline6 mentions / 3d
01122Mentions · 2026-02-05: 2Mentions · 2026-02-06: 2Mentions · 2026-02-09: 2Active Exploitation · 2026-02-06: 1Patch / Workaround · 2026-02-05: 2Patch / Workaround · 2026-02-06: 2Patch / Workaround · 2026-02-09: 1Technical Details · 2026-02-05: 2Technical Details · 2026-02-09: 102-0502-0602-09
Signal classification2 categories
Patch
583.3%
General
116.7%
Referenced assets32 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-052
Patch2
2026-02-062
Patch2
2026-02-092
General1Patch1
Full discourse6 posts
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Cisco ❗ CVE-2026-20119 ❗ CVE-2026-20098 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-cisco-9/ https://t.co/K0F9AEs7HT

    Post summary

    The post announces two Cisco CVEs and links to external information, but provides no details on the vulnerability, exploitation, or mitigation.

    00010157
    6.6K followersView on X
  • Machina Record@MachinaRecord
    Patch

    🩹シスコとF5が深刻度の高い脆弱性を複数件修正(CVE-2026-20119、CVE-2026-22548他) 〜サイバーアラート2月6日〜 https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/43806/

    Post summary

    Cisco and F5 have released patches for multiple high‑severity vulnerabilities, including CVE‑2026‑20119 and CVE‑2026‑22548, as announced in a cyber alert.

    00010169
    1.2K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Multiple vulnerabilities in #Cisco products, notably CVE-2026-20119 leading to unauthenticated DoS in #RoomOS Software and CVE-2026-20098 an improper input validation vulnerability in Meeting Management. For more information: https://sec.cloudapps.cisco.com/security/center/publicationListing.x #Patch #Patch #Patch

    Post summary

    The post highlights two Cisco CVEs, describes their impacts (DoS and input validation), and points to Cisco’s patch information via a security center link.

    01000228
    7.2K followersView on X
  • CyberWarZone@cyberwarzo44531
    Patch

    ⚠️ Cisco has disclosed CVE-2026-20119 (unauthenticated DoS in RoomOS/TelePresence) and CVE-2026-20098 (authenticated arbitrary file upload → root in Meeting Management). Patch ASAP. No exploits seen yet. #Cisco #CVE #CyberSecurity #InfoSec #Vulnerability #PatchNow

    Post summary

    Cisco disclosed two CVEs—an unauthenticated DoS and an authenticated privilege‑escalation via arbitrary file upload—and urges immediate patching; no exploitation has been reported.

    0000086
    26 followersView on X
  • Machina Record@MachinaRecord
    Patch

    【リンク集:2月5日〜6日のセキュリティ関連ニュース/記事】 <脆弱性> ・シスコとF5が深刻度の高い脆弱性を複数件修正(CVE-2026-20119、CVE-2026-22548他) https://www.securityweek.com/cisco-f5-patch-high-severity-vulnerabilities/ ・米CISA、React Native Community CLIやSmarterTools SmarterMailの脆弱性をKEVカタログに追加(CVE-2025-11953、CVE-2026-24423他) https://www.cisa.gov/known-exploited-vulnerabilities-catalog <マルウェア・その他脅威> ・制裁対象の防弾ホスティングプロバイダー、古い家庭用ルーターの乗っ取りに関与 https://hackread.com/sanctioned-bulletproof-host-hijack-old-home-routers/ ・謎のサイバー脅迫グループ0apt、ランダムノイズで大量の機微データを偽造 https://databreach.com/news/44-how-0apt-is-using-random-noise-to-fake-a-ransomware-empire ・SystemBCマルウェアがデバイス1万台に感染、テイクダウンをものともせず https://www.securityweek.com/systembc-infects-10000-devices-after-defying-law-enforcement-takedown/ ・GitHub CodespaceでのVS Code構成設定の自動実行、サプライチェーン攻撃につながる恐れ https://www.securityweek.com/vs-code-configs-expose-github-codespaces-to-attacks/ <ランサムウェア> ・ランサムウェアグループがISPsystemのVMを悪用、ステルス性の高いペイロードを拡散 https://www.bleepingcomputer.com/news/security/ransomware-gang-uses-ispsystem-vms-for-stealthy-payload-delivery/ <データ侵害/サイバー犯罪> ・Zendesk悪用したスパム攻撃が再発 大量の「アカウントを有効化」メールが届く https://www.bleepingcomputer.com/news/security/zendesk-spam-wave-returns-floods-users-with-activate-account-emails/ ・フィンテック企業Bettermentがデータ侵害に遭い、アカウント140万件が流出 https://www.bleepingcomputer.com/news/security/data-breach-at-fintech-firm-betterment-exposes-14-million-accounts/ ・ニュースレタープラットフォームSubstackがデータ侵害をユーザーに通知 https://www.bleepingcomputer.com/news/security/newsletter-platform-substack-notifies-users-of-data-breach/ ・スペイン科学省がシステムを停止 侵害の主張受け https://www.bleepingcomputer.com/news/security/spains-ministry-of-science-shuts-down-systems-after-breach-claims/ ・ルーマニアの石油パイプライン事業者Conpet、サイバー攻撃を公表 https://www.bleepingcomputer.com/news/security/romanian-oil-pipeline-operator-conpet-discloses-cyberattack-qilin-ransomware/ ・政府系テクノロジー大手Conduentのデータ侵害、米国で広範囲に影響及ぶ https://techcrunch.com/2026/02/05/data-breach-at-govtech-giant-conduent-balloons-affecting-millions-more-americans/ ・ローマ大学ラ・サピエンツァ、サイバー攻撃受けオフラインに https://www.bleepingcomputer.com/news/security/italian-university-la-sapienza-goes-offline-after-cyberattack/ <AI関連> ・OpenClaw、簡単なクラックで重要な個人情報を流出させることが判明 https://www.theregister.com/2026/02/05/openclaw_skills_marketplace_leaky_security/ ・法律事務所に偽装した150超のドメインから成るネットワーク、AI活用した詐欺キャンペーンで見つかる https://www.securityweek.com/researchers-expose-network-of-150-cloned-law-firm-websites-in-ai-powered-scam-campaign/ ・英国の「世界初」ディープフェイク検出フレームワーク、偽造防止に役立つ可能性は低いと専門家が指摘 https://www.theregister.com/2026/02/05/uk_government_deepfake_framework/ <サイバー戦/APT/国家型アクター/地政学関連> ・サイバースパイ集団、37か国の政府機関や重要インフラをハッキング https://www.securityweek.com/cyberspy-group-hacked-governments-and-critical-infrastructure-in-37-countries/ ・イタリア、冬季五輪狙った「ロシア発」サイバー攻撃への対応を開始 https://www.theregister.com/2026/02/05/winter_olympics_russian_attacks/ ・ラテンアメリカにおけるデジタル主権 地政学的監視の課題と組織犯罪リスク https://dialogo-americas.com/articles/digital-sovereignty-in-latin-america-the-geopolitical-surveillance-challenge-and-organized-crime-risk/ ・イランのハッカーInfyが新たなC2サーバーで活動再開 政府によるネット遮断の終了に伴い https://thehackernews.com/2026/02/infy-hackers-resume-operations-with-new.html <プライバシー> ・スマートグラスの流行再来、プライバシー問題は未解決 https://www.helpnetsecurity.com/2026/02/05/ai-smart-glasses-privacy-risk/ ・Flock製カメラ、ナンバープレートデータを無許可で米政府機関と共有 https://www.malwarebytes.com/blog/privacy/2026/02/flock-cameras-shared-license-plate-data-without-permission <リサーチ/攻撃手法/TTP> ・不正な「PDF」を開くと攻撃者にPCを遠隔操作される恐れ https://www.malwarebytes.com/blog/news/2026/02/open-the-wrong-pdf-and-attackers-gain-remote-access-to-your-pc ・Marco Stealerの技術分析 https://www.zscaler.com/blogs/security-research/technical-analysis-marco-stealer <政府/政策> ・米CISA、連邦政府各機関に1年以内のEoLデバイス撤去を指示 https://therecord.media/cisa-gives-federal-agencies-one-year-end-of-life-devices ・米上院議員、ICEとCBPに顔認識技術の使用を禁止する法案を提出 https://arstechnica.com/tech-policy/2026/02/ice-out-of-our-faces-act-would-ban-ice-and-cbp-use-of-facial-recognition/ <その他> ・生のエンコード済み添付ファイルから、検閲前のエプスタイン関連PDFを復元する方法 https://neosmart.net/blog/recreating-epstein-pdfs-from-raw-encoded-attachments/ ・マイクロソフト、セキュリティ重視のオープンソースライブラリOS「LiteBox」を発表 https://www.helpnetsecurity.com/2026/02/05/microsoft-litebox-security-focused-open-source-library-os/

    Post summary

    The post highlights that Cisco and F5 have released patches for several high‑severity CVEs, while CISA’s KEV catalog lists related vulnerabilities as known exploits, underscoring the need for timely remediation.

    00000231
    1.2K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Cisco & F5 patch high-severity bugs: unauth TelePresence DoS + Cisco Meeting Management root RCE Cisco fixed CVE-2026-20119 (unauthenticated remote DoS via crafted meeting invite) and CVE-2026-20098 (authenticated arbitrary file upload leading to root command execution in Cisco Meeting Management), while F5’s Feb 2026 advisories include high-rated BIG-IP/NGINX issues such as CVE-2026-22548 that can restart critical processes and disrupt traffic. 🎯 Target: Global/Enterprise (Cisco Collaboration + F5 BIG-IP/NGINX) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.securityweek.com/cisco-f5-patch-high-severity-vulnerabilities/

    Post summary

    The article announces that Cisco and F5 have released patches for several high‑severity vulnerabilities, detailing the nature of the flaws but not evidence of active exploitation or PoCs.

    0000052
    192 followersView on X

Explore more