Zoom Security Update – 21 January 2026

Zoom has released a security update to address a critical vulnerability in Zoom Node Multimedia Routers (MMRs) before version 5.2.1716.0.

The addressed vulnerability could allow the attacker to act as a meeting participant and conduct remote code execution of the Zoom Node Multimedia Routers MMRsand gain access to the affected system.

Zoom Node Deployments – Command Injection Vulnerability (CVE-2026-22844):

  • CVSS: 9.9
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Gain access

The affected products:

  • Zoom Node Meetings Hybrid MMR module versions before 5.2.1716.0.
  • Zoom Node Meeting Connector MMR module versions before 5.2.1716.0.
Vulnerabilities

CVE-2026-22844

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Zoom Security Advisory

References