Cisco Product Security Update Advisory

Cisco Product Security Update Advisory

Overview


Security updates have been released to address several vulnerabilities in Cisco products. The affected products are Cisco RoomOS, Cisco Catalyst Center, Cisco Catalyst Center Global Manager, and Secure Endpoint Connector for Linux/Mac/Windows.

Key Vulnerabilities


  • CVE-2026-20150 in Cisco RoomOS is an improper access control vulnerability.
  • CVE-2026-20153 in Cisco RoomOS is an improper input validation vulnerability.
  • CVE-2026-20156 in Cisco RoomOS is a vulnerability related to insufficient restrictions on operations within memory buffer boundaries.
  • CVE-2026-20157 in Cisco RoomOS is a vulnerability related to lack of encryption.
  • CVE-2026-20158 in Cisco RoomOS is a vulnerability related to insufficient resource lifecycle management.
  • CVE-2026-20187 in Cisco RoomOS is a vulnerability related to insufficient exception handling.
  • CVE-2026-20191 in Cisco Catalyst Center is an arbitrary file read vulnerability.
  • CVE-2026-20213, CVE-2026-20214, CVE-2026-20215, CVE-2026-20216, CVE-2026-20217, CVE-2026-20243, and CVE-2026-20244 are denial-of-service vulnerabilities caused by memory corruption or integer overflow, among other issues.

Affected Systems and Update Versions


  • Cisco RoomOS requires version 11.32.6.0 Or later, or 26.5.2.2 Or later for On-Premises Operation.
  • For Cloud-Aware Operation, Cisco RoomOS requires version 11.39.1.1 Or higher, or RoomOS June 2026 (26.7.1.7) Or higher.
  • Cisco Catalyst Center hardware appliances and AWS and Azure virtual appliances require version 3.1.6 GSMU200 or higher.
  • Cisco Catalyst Center Virtual Appliances on VMware ESXi require version 2.3.7.11-VA GSMU100 or later, or version 3.1.6 GSMU200 or later.
  • Cisco Catalyst Center Global Manager requires Cisco CCGM 1.4.1 Or later.
  • Secure Endpoint Connector requires version 1.29.0 Or later for Linux, 1.27.2 Or later for Mac, and 8.6.2 Or later for Windows.

References


The published reference sites are “Cisco RoomOS Security Hardening Release: July 2026,” “Cisco Catalyst Center Arbitrary File Read Vulnerability,” and “ClamAV Vulnerabilities Affecting Cisco Products: July 2026.”