Junglewise Threat Intelligence

CVE-2026-20158: Cisco RoomOS improper resource control denial of service

CVE-2026-20158 · Severity: high · CVSS 7.5 · Published 2026-07-15

Technologies: Cisco RoomOS Software. Vendors: Cisco.

Executive brief

Cisco RoomOS, the operating system for Cisco collaboration and video conferencing devices, is affected by resource management vulnerabilities. An attacker could exploit these issues to cause a denial of service, potentially disrupting business meetings and communication services. Cisco has released software updates to address these issues, which were discovered during internal security reviews.

Technical details

Cisco RoomOS contains vulnerabilities related to improper control of a resource through its lifetime (CWE-664), including issues such as uninitialized variables and null pointer dereferences. These vulnerabilities were identified during an internal security hardening review. According to the CVSS vector (AV:N/AC:L/PR:N/UI:N), the most impactful of these issues can be exploited remotely over the network without authentication or user interaction, resulting in a high impact on availability (denial of service). Cisco has released RoomOS 11.32.6.0, 11.39.1.1, and June 2026 (26.7.1.7) to remediate these issues.

Affected products

  • Cisco RoomOS Software 11 and earlier; 26; 26.5.2.2

Timeline

  • 2026-07-15: advisory
  • 2026-07-15: patched

References

Related threats