Cisco issued a high-severity advisory and patches for Cisco Meeting Management addressing CVE-2026-20098 (reported as CVSS 8.8), an authenticated remote arbitrary file upload flaw in the product’s Certificate Management web interface. Due to improper input validation, an attacker with valid credentials—requiring as little as the “video operator” role—can send crafted HTTP requests to upload malicious files that may overwrite system files and be processed by the root account, enabling arbitrary command execution and privilege escalation to root.
Cisco also released fixes for a separate issue in its video endpoint software: CVE-2026-20119 (reported as CVSS 7.5) affecting Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS, where a flaw in the text rendering subsystem can allow an unauthenticated remote attacker to trigger a denial-of-service (DoS) condition on affected devices. Organizations running these collaboration platforms should prioritize applying the vendor updates, particularly where Meeting Management is exposed to users beyond tightly controlled admin groups.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Cisco released security updates addressing CVE-2026-20098 in Cisco Meeting Management and CVE-2026-20119, an unauthenticated denial-of-service issue in Cisco TelePresence CE Software and RoomOS that can be triggered by crafted rendered text such as a meeting invitation. Fixed versions include Meeting Management 3.12.1 MR or later and specified RoomOS/firmware releases, and Cisco said there were no reports of in-the-wild exploitation.
The NATO Cyber Security Centre Penetration Testing Team reported CVE-2026-20098, a flaw in Cisco Meeting Management's Certificate Management feature that lets an authenticated low-privilege user upload arbitrary files, execute commands, and gain root privileges. The exact report date is not stated in the references.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.