CVE-2026-22844: Zoom Node Deployments - Command Injection
Published Jan 20, 2026
·Updated
A Command Injection vulnerability in Zoom Node Multimedia Routers (MMRs) before version 5.2.1716.0 may allow a meeting participant to conduct remote code execution of the MMR via network access.
Affected Software
1 affected component
Zoom Node Multimedia Routers<5.2.1716.0
Event History
Jan 20, 2026
CVE Published
via MITRE·01:57 PM
Data Sourced
via MITRE·01:57 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeakness
Apr 20, 58071
Event
via FIRST·08:28 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-22844?
The severity of CVE-2026-22844 is considered high due to its potential for remote code execution.
2
How do I fix CVE-2026-22844?
To fix CVE-2026-22844, upgrade Zoom Node Multimedia Routers to version 5.2.1716.0 or later.
3
What impact does CVE-2026-22844 have on affected systems?
CVE-2026-22844 allows unauthorized command injection, leading to potential remote code execution on the affected systems.
4
Who is affected by CVE-2026-22844?
Organizations using Zoom Node Multimedia Routers versions prior to 5.2.1716.0 are affected by CVE-2026-22844.
5
When was CVE-2026-22844 reported?
CVE-2026-22844 was reported in a security bulletin that outlines vulnerabilities affecting Zoom Node Multimedia Routers.