CybersecurityCritical Security Patches Released for Zoom and GitLab

Critical Security Patches Released for Zoom and GitLab

Key Takeaways

  • Zoom and GitLab have released security updates to resolve multiple security vulnerabilities that could result in denial-of-service (DoS) and remote code execution.
  • A critical security flaw in Zoom Node Multimedia Routers (MMRs) could permit a meeting participant to conduct remote code execution attacks, with a CVSS score of 9.9 out of 10.0.
  • GitLab has released fixes for multiple high-severity flaws affecting its Community Edition (CE) and Enterprise Edition (EE) that could result in DoS and a bypass of two-factor authentication (2FA) protections.
  • The vulnerabilities affect various versions of Zoom and GitLab products, and users are recommended to update to the latest available versions to safeguard against potential threats.

Introduction to Security Vulnerabilities
The recent release of security updates by Zoom and GitLab aims to address several security vulnerabilities that could have severe consequences, including denial-of-service (DoS) and remote code execution. These vulnerabilities were discovered internally by the companies’ security teams and through external researchers, highlighting the importance of continuous security testing and vulnerability detection. The most severe vulnerability affects Zoom Node Multimedia Routers (MMRs), which could allow a meeting participant to conduct remote code execution attacks. This vulnerability, tracked as CVE-2026-22844, has a CVSS score of 9.9 out of 10.0, indicating a critical severity level.

Zoom Node Multimedia Routers Vulnerability
The vulnerability in Zoom Node Multimedia Routers (MMRs) is a command injection vulnerability that could allow a meeting participant to conduct remote code execution attacks via network access. According to Zoom, the vulnerability affects the following versions: Zoom Node Meetings Hybrid (ZMH) MMR module versions prior to 5.2.1716.0 and Zoom Node Meeting Connector (MC) MMR module versions prior to 5.2.1716.0. Zoom recommends that customers using Zoom Node Meetings, Hybrid, or Meeting Connector deployments update to the latest available MMR version to safeguard against any potential threat. Fortunately, there is no evidence that the security flaw has been exploited in the wild, and users can take proactive measures to protect themselves by updating their software.

GitLab Security Flaws
In addition to the Zoom vulnerability, GitLab has released fixes for multiple high-severity flaws affecting its Community Edition (CE) and Enterprise Edition (EE). These flaws could result in DoS and a bypass of two-factor authentication (2FA) protections. The vulnerabilities are listed as follows: CVE-2025-13927, CVE-2025-13928, and CVE-2026-0723, with CVSS scores of 7.5, 7.5, and 7.4, respectively. These vulnerabilities affect various versions of GitLab, including versions from 11.9 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2. GitLab has also remediated two other medium-severity bugs, CVE-2025-13335 and CVE-2026-1102, which could trigger a DoS condition by configuring malformed Wiki documents and sending repeated malformed SSH authentication requests, respectively.

Importance of Security Updates
The release of security updates by Zoom and GitLab highlights the importance of regular software updates and vulnerability patches. These updates are crucial in protecting users against potential threats and preventing malicious actors from exploiting known vulnerabilities. Users are recommended to update their software to the latest available versions to ensure they have the latest security patches and features. Additionally, users should be aware of the potential risks associated with using outdated software and take proactive measures to protect themselves, such as implementing robust security measures, including firewalls, antivirus software, and intrusion detection systems.

Conclusion and Recommendations
In conclusion, the recent security updates released by Zoom and GitLab demonstrate the ongoing efforts to identify and address security vulnerabilities in software products. The vulnerabilities highlighted in this article, including the critical security flaw in Zoom Node Multimedia Routers (MMRs) and the high-severity flaws in GitLab, emphasize the importance of regular software updates and vulnerability patches. Users are recommended to update their software to the latest available versions and take proactive measures to protect themselves against potential threats. By staying informed about the latest security vulnerabilities and taking steps to mitigate them, users can help ensure the security and integrity of their systems and data.

- Advertisement -spot_img

More From UrbanEdge

Fake Job Recruiters’ Malware in Developer Coding Challenges

Cybercriminals are exploiting developer job hunts by embedding malware in coding challenges. These attacks are effective as they leverage routine aspects of the developer workflow. Fake recruiters promise unrealistic salaries while embedding malicious code, making vigilance crucial for job-seekers in the tech industry...

Business Data, Emails & Browsing History Theft by Malicious Chrome Extensions

Cybercriminals exploit Chrome extensions to access confidential business data, emails, and browsing history from millions of users. These malicious tools often disguise themselves as legitimate productivity extensions, putting unsuspecting users at risk. Discover how to identify threats and protect your sensitive information from stealthy cyber intrusions...

Valentine’s Day Cyber Threats & Risks: Protect Yourself

Valentine's Day creates a perfect storm for cybercriminals, with romance scams accounting for $697 million in losses and phishing attempts spiking by 28%. Protect yourself by employing security measures like two-factor authentication and understanding swift actions post-scam to minimize risk and financial damage...

PlayStation 2026 State of Play Games Reveals & Announcements

PlayStation's 2026 State of Play unveiled over 15 new titles, including a surprise God of War spin-off and a remake of the original trilogy. Fans thrilled over the John Wick game reveal featuring Keanu Reeves, with new IPs and third-party revivals like Castlevania also showcased...

Queensland Flood Alerts: Storms to End Extreme Heatwave

Queensland Flood Alerts: Storms to End Extreme Heatwave Projected Rainfall...

Queensland Flood Warning, Alerts & Weekend Forecast

Queensland braces for heavy rain and potential flooding as a low-pressure trough stalls over the state. With predicted rainfall of 100-300mm through Sunday, authorities urge preparedness. SE regions may face disruptions, extending the alert to northeast New South Wales. Prepare emergency kits and plans now...

Brisbane Flood Risk: Storms Predicted to End Heatwave

Brisbane residents brace for storms set to end the relentless heatwave. Expect heavy rainfall, with up to 150mm in some areas, increasing flood risks, especially in low-lying regions. Flash floods are possible, and temperatures could drop by 10 degrees. Prepare emergency kits and stay updated on weather developments...

Apple Zero-Day Fix: Sophisticated Attack Solution & Patch

Apple has urgently patched two zero-day vulnerabilities in WebKit used in highly complex attacks targeting specific individuals. Security experts emphasize immediate updates to protect against these threats, linked to advanced actors, possibly nation-states. The overlapping nature of these exploits suggests a coordinated effort...

Windows 11 Notepad Vulnerability: Silent File Execution via Markdown Links

A critical vulnerability in Windows 11 Notepad's Markdown feature allows remote code execution via malicious links, posing a serious risk to users. Microsoft has issued a patch, but immediate updates and extra defenses are essential to prevent exploitation and ensure secure computing environments...
- Advertisement -spot_img