CVE-2026-20153 – Cisco RoomOS Software

CVSS 7.5 IMPORTANT High with EoP or RCE – Expedited Deployment

“Multiple weaknesses across access, memory, encryption, and error handling can expose critical collaboration systems.”

Cisco released a RoomOS software-hardening update addressing six internally discovered, high-severity vulnerabilities. The update strengthens access controls, memory handling, input validation, encryption, resource lifecycle management, and exceptional-condition handling. The most serious weaknesses could enable privilege escalation or arbitrary code execution.

CVE-2026-20150 has a CVSS score of 8.8, High severity. CVE-2026-20156 has a CVSS score of 8.1, High severity. CVE-2026-20153 has a CVSS score of 7.5, High severity. CVE-2026-20157 has a CVSS score of 7.5, High severity. CVE-2026-20158 has a CVSS score of 7.5, High severity. CVE-2026-20187 has a CVSS score of 7.5, High severity.

Key Details

Affected Product
Cisco Roomos
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-20
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.