logo

Zoom and GitLab Patch RCE, DoS, and 2FA Bypass Vulnerabilities

ID: 694c062a-ff69-5cdc-9e28-ba7d9d6ef545

STIX ID: report--694c062a-ff69-5cdc-9e28-ba7d9d6ef545

Feed Name: TechRepublic Security

Threat Score
80/100

Date Published: 2026-01-22

Date Updated: 2026-04-23

Author: TechRepublic Staff

...
...

Urgent security bulletin: Zoom released an emergency patch for CVE-2026-22844 — a command-injection RCE in Zoom Node Multimedia Routers (MMR) that can allow a meeting participant to execute commands and potentially compromise enterprise network infrastructure — while GitLab issued patches for multiple high-severity issues (including CVE-2025-13927 allowing unauthenticated DoS and other authentication/JSON validation flaws) that could crash development operations; organizations are advised to immediately update Zoom MMR to 5.2.1716.0+ and apply the latest GitLab patches. The report also notes an active phishing campaign targeting LastPass customers, increasing the short-term threat activity against enterprise users.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.