Now available: Connect for Teams Rooms on Android. Learn more

Pexip Security Bulletin
26-01

Published: 27 July 2026

Last updated: 09:00 UTC, 27 July 2026

Critical security vulnerability in Pexip Infinity

 

A critical security vulnerability in Pexip Infinity has been identified during a controlled security test. This vulnerability, which has a CVSS3.1 score of 9.8, is present in all versions of Pexip Infinity released prior to those identified in the resolution below. All customers should upgrade to v38.2, v39.2, v40.1, or v41 as soon as possible. This includes customers using Pexip Infinity purely for One-Touch Join functionality.

 

Further details on the vulnerability and fixed versions are available at: https://docs.pexip.com/admin/security_bulletins.htm

 

 

How do I upgrade?

 

Pexip Platform Downloads are available at:

 

Release notes are available for each of the fixed versions, at:

 

Note that upgrades from earlier versions may require steps during the upgrade process; this is covered in the notes above and the guide at: https://docs.pexip.com/admin/upgrading.htm

 

 

What about Teams Connectors? 

 

If you are not changing major version (e.g. upgrading from v40.0 to v40.1), you do not need to re-deploy your Teams Connector. 

 

 

What about other Pexip Products?

 

This vulnerability only affects the Pexip Infinity software; it does not directly impact AIMS, scheduling, or any other independent Pexip product. 

 

 

What if I cannot upgrade immediately? 

 

Please reach out to your Authorized Pexip Support Representative to discuss temporary mitigation options. 

 

 

Was Pexip breached directly? Did Pexip leak customer data? 

 

No.  Pexip was not breached and did not leak any customer data.  This is purely a software vulnerability on the Infinity product software.  

 

 

What about the Pexip Cloud Service? 

 

The Pexip Cloud Service is unaffected by this issue.