CVE-2026-22844Patch

MEDIUMCVSS 9.9 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A Command Injection vulnerability in Zoom Node Multimedia Routers (MMRs) before version 5.2.1716.0 may allow a meeting participant to conduct remote code execution of the MMR via network access.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 5 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-02-06); latest day: 1
  • 6 total mentions across 5 days

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-01-28: 1Mentions · 2026-01-29: 1Mentions · 2026-02-03: 1Mentions · 2026-02-06: 2Mentions · 2026-02-12: 1Active Exploitation · 2026-01-28: 1Patch / Workaround · 2026-01-28: 1Patch / Workaround · 2026-02-03: 1Patch / Workaround · 2026-02-06: 1Patch / Workaround · 2026-02-12: 1Technical Details · 2026-01-28: 1Technical Details · 2026-01-29: 1Technical Details · 2026-02-03: 1Technical Details · 2026-02-06: 201-2801-2902-0302-0602-12
Signal classification3 categories
Patch
466.7%
Disclosure
116.7%
General
116.7%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-01-281
Patch1
2026-01-291
Disclosure1
2026-02-031
Patch1
2026-02-062
General1Patch1
2026-02-121
Patch1
Full discourse6 posts
  • transilienceai@transilienceai
    Patch

    🚨 Zoom Node Multimedia Routers [—] Feb 06, 2026 Comprehensive security advisory dissecting a high-risk command injection vulnerability (CVE-2026-22844) in Zoom Node Multimedia Routers, its business impact, and detailed mitigation strategy. Checkout our Threat Intelligence... https://t.co/eYuJs986EV

    Post summary

    Comprehensive advisory on CVE‑2026‑22844, a high‑risk command injection flaw in Zoom Node Multimedia Routers, outlining business impact and mitigation steps.

    1000064
    316 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Zoom Node MMR の深刻な脆弱性 CVE-2026-22844 が FIX:コマンド・インジェクションによる RCE の恐れ https://iototsecnews.jp/2026/01/21/critical-zoom-command-injection-vulnerability-enables-remote-code-execution/ Zoom のハイブリッド運用 (Zoom Node) を支えるコンポーネント MultiMedia Router (MMR) において、会議の参加者にシステムの完全な乗っ取りを許す、きわめて深刻な脆弱性が見つかりました。この問題の原因は、プログラムが外部からの命令を処理する際のコマンド・インジェクションという不備にあります。 この脆弱性 CVE-2026-22844 (CVSS:9.9:Critical) は、最大級の警戒が必要な脅威となっています。一般的なユーザー権限を持つ会議の参加者であれば、特別な知識がなくてもネットワーク経由でMMRサーバ上での任意のプログラム実行が可能になります。ご利用のチームは、ご注意ください。 #CVE202622844 #NodeMMR #Vulnerability #Zoom

    Post summary

    The article announces a critical command‑injection flaw (CVE‑2026‑22844) in Zoom Node MMR that enables remote code execution by regular users, but it provides no evidence of exploitation, PoC, or specific patch information.

    01000132
    485 followersView on X
  • tunastech.id@tunastech_id
    Patch

    Zoom kena celah CVE-2026-22844 (skor 9.9/10)! Hacker bisa ambil alih server tanpa login. Target: Hybrid Meeting & Meeting Connector. Risiko: data rapat bocor, server dikuasai. Solusi: Update app NOW, pakai password meeting, aktifkan waiting room. #tunastech https://t.co/9f34S3jXnd

    Post summary

    Zoom CVE-2026-22844 is a critical vulnerability; users are advised to update the app and apply recommended security settings to mitigate the risk.

    0000050
    260 followersView on X
  • Soo Yoon | FailSafe Ecosystem@sooyoon_eth
    General

    @transilienceai zoom node router command injection is nasty. cve-2026-22844 shows how network infrastructure vulnerabilities can cascade into much bigger problems if not patched fast

    Post summary

    The tweet highlights a command injection vulnerability (CVE‑2026‑22844) in a Zoom node router, warning that failure to patch promptly could lead to cascading network problems.

    0000056
    23.7K followersView on X
  • transilienceai@transilienceai
    Patch

    🚨 Zoom Node Multimedia Routers [—] Feb 03, 2026 Critical security advisory for Zoom Node Multimedia Routers: Command injection flaw (CVE-2026-22844) enabling potential remote code execution. Affected deployments must upgrade urgently. Checkout our Threat Intelligence Platform:...

    Post summary

    A critical command injection vulnerability (CVE‑2026‑22844) in Zoom Node Multimedia Routers allows remote code execution; affected deployments are urged to apply patches urgently.

    0000063
    317 followersView on X
  • Ostorlab@OstorlabSec
    Patch

    🚨 CVE-2026-22844 : CRITICAL COMMAND INJECTION ALERT 🚨 @Zoom  A command injection vulnerability has been disclosed in Zoom Node Multimedia Routers (MMRs) — core infrastructure responsible for routing real-time audio/video in enterprise Zoom deployments. Risk Severity: Critical (CVSS 9.9, active exploitation, trending, ransomware-relevant) Impact: • Arbitrary command execution as root • Full compromise of Zoom MMR infrastructure • Real-time interception of confidential meetings • Persistent backdoors & rootkits • Lateral movement into adjacent Zoom infrastructure Root Cause: CWE-78 (OS Command Injection). Zoom MMR fails to sanitize participant-controlled media parameters, which are concatenated into shell commands during stream configuration and executed with elevated privileges. Attackers can: • Join a Zoom meeting as an authenticated participant (including guests) • Inject malicious payloads via media negotiation metadata • Execute arbitrary system commands as root • Intercept, manipulate, or record audio/video streams • Pivot across clustered MMR nodes Are You Affected? Vulnerable: Zoom Node MMR < 5.2.1716.0 Scope: On-prem and private-cloud Zoom Node deployments Immediate Action Required: Update: Upgrade to Zoom Node MMR 5.2.1716.0+ immediately Mitigation: Restrict external meeting access; isolate MMRs on dedicated VLANs Audit: Hunt for shell processes spawning from MMR services and anomalous outbound traffic Meeting infrastructure is now a Tier-0 ransomware target. Patch without delay. 🛡️ #zoom #security #ostorlabCVE

    Post summary

    The post announces a critical Zoom MMR command injection (CVE‑2026‑22844) with active exploitation and supplies immediate patch and mitigation guidance.

    0000071
    581 followersView on X

Explore more