Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026012204013636 | Publication Time | 2026/01/22 16:43 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026/01/22 16:43 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】A Critical Security Vulnerability Has Been Identified in Zoom Node Media Router (CVE-2026-22844) |
|||
| [Content] Forwarded from TWCERTCC-200-202601-00000018 Zoom Node Multimedia Routers (MMRs) are core modules of Zoom’s hybrid cloud solution, primarily used to process meeting media traffic, improve bandwidth efficiency, and reduce latency. Recently, Zoom released a critical security advisory (CVE-2026-22844, CVSS: 9.9). This vulnerability is a command injection vulnerability that may allow meeting participants to execute remote code on MMRs via network access. (Information Sharing Level: WHITE (Information content can be publicly disclosed) |
|||
|
[Affected Platform] Zoom Node Meeting Connector (MC) MMR module versions earlier than 5.2.1716.0 (exclusive) |
|||
| [Recommended Actions] Apply the remediation measures in accordance with the solution released on the official website: https://www.twcert.org.tw/tw/cp-169-10648-b83d7-1.html |
|||
| [Reference] https://www.twcert.org.tw/tw/cp-169-10648-b83d7-1.html |
|||