Zoom and GitLab Patch RCE, DoS, and 2FA Bypass Vulnerabilities
ID: 694c062a-ff69-5cdc-9e28-ba7d9d6ef545
STIX ID: report--694c062a-ff69-5cdc-9e28-ba7d9d6ef545
Feed Name: TechRepublic Security
Urgent security bulletin: Zoom released an emergency patch for CVE-2026-22844 — a command-injection RCE in Zoom Node Multimedia Routers (MMR) that can allow a meeting participant to execute commands and potentially compromise enterprise network infrastructure — while GitLab issued patches for multiple high-severity issues (including CVE-2025-13927 allowing unauthenticated DoS and other authentication/JSON validation flaws) that could crash development operations; organizations are advised to immediately update Zoom MMR to 5.2.1716.0+ and apply the latest GitLab patches. The report also notes an active phishing campaign targeting LastPass customers, increasing the short-term threat activity against enterprise users.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
