Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Cisco RoomOS Security Hardening Release - Missing Encryption Vulnerabilities
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U H H H 9.8 .0011 1.3 —
AFFECTED
Product Versions Fixed
Cisco RoomOS Software RoomOS 10.11.2.2 – —
TIMELINE
Oct 8 Reserved by cisco
Jul 15 Published (CNA: cisco)
Aug 14 RESCORED — CVE-2026-20157 (Cisco RoomOS Software). CVSS 7.5 → 9.8 (NVD).
Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.
The vulnerabilities tracked by CVE-2026-20157 are related to missing encryption that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-311.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| October 8, 2025 | Reserved | Reserved by cisco |
| July 15, 2026 | Published | Published (CNA: cisco) |
| August 14, 2026 | RESCORED | RESCORED — CVE-2026-20157 (Cisco RoomOS Software). CVSS 7.5 → 9.8 (NVD). |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Cisco | Cisco RoomOS Software | — | RoomOS 10.11.2.2 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-20157 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.