HomeUpdatesZoom and GitLab fix serious vulnerabilities

Zoom and GitLab patch serious vulnerabilities

Zoom and GitLab have released security updates to resolve several vulnerabilities that could lead to attacks denial-of-service (DoS) and remote code execution ( RCE)

GitLab Zoom

Zoom vulnerability fix

The most serious vulnerability affects Zoom Node Multimedia Routers (MMRs) and could allow a meeting participant to conduct remote code execution. This vulnerability, listed as CVE-2026-22844 and discovered by Zoom's Offensive Security team, has a CVSS score of 9.9 out of 10.0.

See also: Cisco fixes zero-day vulnerability in Unified CM and Webex

“ A command injection in Zoom Node Multimedia Routers (MMRs), prior to version 5.2.1716.0, could allow a meeting participant to remotely execute code on the MMR via network access vulnerability ,” the company noted in an advisory

Zoom recommends that customers using the Zoom Node Meetings, Hybrid, or Meeting Connector update to the latest available MMR version to protect themselves from potential threats. There is no indication that this vulnerability has been used in attacks. The vulnerability affects the following versions:

– Zoom Node Meetings Hybrid (ZMH) MMR module versions prior to 5.2.1716.0

– Zoom Node Meeting Connector (MC) MMR module versions prior to 5.2.1716.0

See also: GitLab: Vulnerability allows bypass of 2FA protection

Zoom and GitLab patch serious vulnerabilities

GitLab Vulnerability Patching

GitLab has also released fixes for multiple high-severity vulnerabilities affecting Community Edition (CE) and Enterprise Edition (EE) . The vulnerabilities could lead to DoS and bypass of two-factor authentication (2FA) protections:

– CVE-2025-13927 (CVSS score: 7.5) – A vulnerability that could allow an unauthorized user to create a DoS condition by sending specially crafted requests with incorrect authentication data.

– CVE-2025-13928 (CVSS score: 7.5) – An incorrect authorization vulnerability in the Releases API that could allow an unauthorized user to cause a DoS condition.

– CVE-2026-0723 (CVSS score: 7.4) – A vulnerability that could allow an individual with knowledge of a victim's credential ID to bypass 2FA by submitting forged device responses.

See also: Binary-parser bug allows code execution in Node.js

Zoom and GitLab patch serious vulnerabilities

Additionally, GitLab has fixed two medium severity vulnerabilities that could also cause a DoS condition (CVE-2025-13335, CVSS score: 6.5, and CVE-2026-1102, CVSS score: 5.3) through malformed Wiki documents bypassing cycle detection and sending repeated bad SSH authentication requests, respectively.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS