# Cisco RoomOS patches multiple vulnerabilities

Published: 2026-07-16 · Severity: medium · Sectors: technology
Canonical: https://vorant.io/reports/8969a4cf-2b95-5dda-bc77-23f4a910e432/cisco-roomos-patches-multiple-vulnerabilities

> ANSSI advisory reports multiple RoomOS vulnerabilities allowing data confidentiality breaches and security policy bypass, fixed in updated versions.

CERT-FR published an advisory describing multiple vulnerabilities in Cisco RoomOS, the software running on Cisco video conferencing endpoints. The flaws could allow an attacker to compromise data confidentiality, bypass security policies, or trigger other unspecified security issues as noted in Cisco's own advisory. Six CVEs are referenced in total, covering RoomOS versions 11 prior to 11.32.6.0 and versions 26 prior to 26.5.2.2.

No evidence of active exploitation is mentioned in the advisory. Cisco has published patches, and affected organizations are advised to update to the corrected versions referenced in the vendor's security bulletin. This is a routine vendor patch advisory rather than a report of an active campaign.

## Mentioned in this report

- Vulnerabilities: CVE-2026-20150, CVE-2026-20153, CVE-2026-20156, CVE-2026-20157, CVE-2026-20158, CVE-2026-20187

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0890

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/8969a4cf-2b95-5dda-bc77-23f4a910e432/cisco-roomos-patches-multiple-vulnerabilities.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
