As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20156 are related to improper restriction of operations within the bounds of a memory buffer that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-119.
Monitor this advisory for an available fix and review any installs of the affected package.
Local check
hol-guard supply-chain scanCisco RoomOS Security Hardening Release - Buffer Management Vulnerabilities affects Cisco/Cisco RoomOS Software (generic). Severity is high. As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20156 are related to improper restriction of operations within the bounds of a memory buffer that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-119.
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Cisco/Cisco RoomOS Softwaregeneric | RoomOS 10.11.2.2 || RoomOS 10.15.2.2 || RoomOS 11.5.4.6 || RoomOS 11.5.2.4 || RoomOS 10.8.2.5 || RoomOS 10.11.5.2 || RoomOS 10.11.3.0 || RoomOS 10.15.5.3 || RoomOS 10.19.2.2 || RoomOS 11.1.3.1 || RoomOS 10.11.6.0 || RoomOS 10.19.3.0 || RoomOS 10.19.4.2 || RoomOS 10.3.2.4 || RoomOS 10.3.4.0 || RoomOS 10.15.3.0 || RoomOS 11.1.4.1 || RoomOS 11.14.2.3 || RoomOS 11.1.2.4 || RoomOS 10.8.3.1 || RoomOS 11.14.2.1 || RoomOS 10.3.3.0 || RoomOS 10.8.4.0 || RoomOS 10.15.4.1 || RoomOS 10.19.5.6 || RoomOS 10.11.4.1 || RoomOS 11.9.3.1 || RoomOS 11.5.3.3 || RoomOS 10.3.2.0 || RoomOS 11.9.2.4 || RoomOS 11.14.3.0 || RoomOS 11.17.2.2 || RoomOS 11.14.4.0 || RoomOS 10.19 StepUpg || RoomOS 11.17.3.0 || RoomOS 11.20.2.3 || RoomOS 11.14.5.0 || RoomOS 11.17.4.0 || RoomOS 11.20.3.0 || RoomOS 11.23.1.6 || RoomOS 11.23.1.8 || RoomOS 11.24.1.5 || RoomOS 11.24.2.4 || RoomOS 11.24.3.0 || RoomOS 11.24.4.1 || RoomOS 11.27.2.0 || RoomOS 11.28.1.3 || RoomOS 11.27.3.0 || RoomOS 11.31.1.5 || RoomOS 11.27.4.0 || RoomOS 11.32.2.1 || RoomOS 11.33.1.7 || RoomOS 26.0.1.2 || RoomOS 11.34.1.2 || RoomOS 11.32.3.0 || RoomOS 11.27.5.0 || RoomOS 11.32.4.0 || RoomOS 26.1.1.5 || RoomOS 11.35.1.2 || RoomOS 26.2.2.2 || RoomOS 11.32.5.1 || RoomOS 26.4.1.6 || RoomOS 26.4.1.4 || RoomOS 26.3.1.3 || RoomOS 11.36.1.1 || RoomOS 11.37.1.0 || RoomOS 26.5.2.0 || RoomOS 11.38.1.1 |
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20156 are related to improper restriction of operations within the bounds of a memory buffer that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-119.
Monitor this advisory for an available fix and review any installs of the affected package.
Local check
hol-guard supply-chain scanCisco RoomOS Security Hardening Release - Buffer Management Vulnerabilities affects Cisco/Cisco RoomOS Software (generic). Severity is high. As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20156 are related to improper restriction of operations within the bounds of a memory buffer that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-119.
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Cisco/Cisco RoomOS Softwaregeneric | RoomOS 10.11.2.2 || RoomOS 10.15.2.2 || RoomOS 11.5.4.6 || RoomOS 11.5.2.4 || RoomOS 10.8.2.5 || RoomOS 10.11.5.2 || RoomOS 10.11.3.0 || RoomOS 10.15.5.3 || RoomOS 10.19.2.2 || RoomOS 11.1.3.1 || RoomOS 10.11.6.0 || RoomOS 10.19.3.0 || RoomOS 10.19.4.2 || RoomOS 10.3.2.4 || RoomOS 10.3.4.0 || RoomOS 10.15.3.0 || RoomOS 11.1.4.1 || RoomOS 11.14.2.3 || RoomOS 11.1.2.4 || RoomOS 10.8.3.1 || RoomOS 11.14.2.1 || RoomOS 10.3.3.0 || RoomOS 10.8.4.0 || RoomOS 10.15.4.1 || RoomOS 10.19.5.6 || RoomOS 10.11.4.1 || RoomOS 11.9.3.1 || RoomOS 11.5.3.3 || RoomOS 10.3.2.0 || RoomOS 11.9.2.4 || RoomOS 11.14.3.0 || RoomOS 11.17.2.2 || RoomOS 11.14.4.0 || RoomOS 10.19 StepUpg || RoomOS 11.17.3.0 || RoomOS 11.20.2.3 || RoomOS 11.14.5.0 || RoomOS 11.17.4.0 || RoomOS 11.20.3.0 || RoomOS 11.23.1.6 || RoomOS 11.23.1.8 || RoomOS 11.24.1.5 || RoomOS 11.24.2.4 || RoomOS 11.24.3.0 || RoomOS 11.24.4.1 || RoomOS 11.27.2.0 || RoomOS 11.28.1.3 || RoomOS 11.27.3.0 || RoomOS 11.31.1.5 || RoomOS 11.27.4.0 || RoomOS 11.32.2.1 || RoomOS 11.33.1.7 || RoomOS 26.0.1.2 || RoomOS 11.34.1.2 || RoomOS 11.32.3.0 || RoomOS 11.27.5.0 || RoomOS 11.32.4.0 || RoomOS 26.1.1.5 || RoomOS 11.35.1.2 || RoomOS 26.2.2.2 || RoomOS 11.32.5.1 || RoomOS 26.4.1.6 || RoomOS 26.4.1.4 || RoomOS 26.3.1.3 || RoomOS 11.36.1.1 || RoomOS 11.37.1.0 || RoomOS 26.5.2.0 || RoomOS 11.38.1.1 |
| Not reported |
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| Not reported |
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard