Junglewise Threat Intelligence

CVE-2026-20153: Cisco RoomOS improper input validation denial of service

CVE-2026-20153 · Severity: high · CVSS 7.5 · Published 2026-07-15

Technologies: Cisco RoomOS. Vendors: Cisco.

Executive brief

Cisco RoomOS is the operating system used by Cisco collaboration and video conferencing devices. A vulnerability in how the system processes incoming data could allow a remote attacker to cause the device to crash or become unavailable. This would disrupt business meetings and communication services until the device is recovered.

Technical details

Multiple vulnerabilities in Cisco RoomOS are categorized under CWE-20 (Improper Input Validation). The root cause is a failure of the software to properly validate input data, which can be exploited by a remote, unauthenticated attacker via the network. A successful exploit allows the attacker to cause a denial of service (DoS) on the affected device. These vulnerabilities were identified during internal testing, including the use of AI models for security review. Cisco has released RoomOS 11.32.6.0 (on-premises), 11.39.1.1 (cloud), and 26.5.2.2 to address these issues.

Affected products

  • Cisco RoomOS Software 11 and earlier; 26 before 26.5.2.2

Timeline

  • 2026-07-15: disclosed
  • 2026-07-15: advisory
  • 2026-07-15: patched

References

Related threats