Executive brief
Cisco RoomOS is the operating system used by Cisco collaboration and video conferencing devices. A vulnerability in how the system processes incoming data could allow a remote attacker to cause the device to crash or become unavailable. This would disrupt business meetings and communication services until the device is recovered.
Technical details
Multiple vulnerabilities in Cisco RoomOS are categorized under CWE-20 (Improper Input Validation). The root cause is a failure of the software to properly validate input data, which can be exploited by a remote, unauthenticated attacker via the network. A successful exploit allows the attacker to cause a denial of service (DoS) on the affected device. These vulnerabilities were identified during internal testing, including the use of AI models for security review. Cisco has released RoomOS 11.32.6.0 (on-premises), 11.39.1.1 (cloud), and 26.5.2.2 to address these issues.
Affected products
- Cisco RoomOS Software 11 and earlier; 26 before 26.5.2.2
Timeline
- 2026-07-15: disclosed
- 2026-07-15: advisory
- 2026-07-15: patched