CyberSecurity

Zoom, GitLab Release Critical Security Patches for Remote Code Execution Vulnerabilities

New York: Zoom and GitLab issued urgent security updates on Wednesday to address critical vulnerabilities that could allow remote code execution and denial-of-service attacks, affecting millions of enterprise users worldwide.

The most severe flaw, ‘CVE-2026-22844 in Zoom Node Multimedia Routers, earned a severity score of 9.9 out of 10’, enabling any meeting participant to potentially execute remote code on enterprise network infrastructure, said a security analysis published by TechRepublic.

The vulnerability affects Zoom Node Multimedia Routers before version 5.2.1716.0, creating what security researchers described as a ‘complete disaster’ scenario for enterprise security. The command injection flaw essentially grants meeting participants unauthorized administrative access to networking equipment.

Also read: Anthropic Unveils Project Glasswing to Find Software Bugs

GitLab simultaneously addressed multiple critical vulnerabilities spanning remote code execution, denial-of-service, and two-factor authentication bypass flaws. The standout threat, CVE-2025-13927, allows “completely unauthenticated attackers to crash GitLab instances by sending specially crafted requests with malformed authentication data,” according to the security bulletin.

Also read: Anthropic Launches Claude Code Security Amid Cybersecurity Selloff

The GitLab vulnerabilities affect Community and Enterprise Editions, with attack vectors ranging from resource exhaustion in event collection to JSON validation exploits in GraphQL requests. CVSS scores range from 6.5 to 8.5 across different vulnerability types, representing what researchers characterized as systemic security challenges across GitLab’s platform architecture.

Both platforms serve as backbone infrastructure for remote work and software development. Organizations are “heavily dependent on these tools for daily operations,” making the “window for exploitation” massive, security analysts warned.

Also read: Why VPNs are Essential for Remote Teams Using Cloud-Based Software?

GitLab’s patches address stored cross-site scripting flaws in GitLab Flavored Markdown, missing authorization bugs in the Duo Workflows API, and denial-of-service vulnerabilities in import functionality. The company deployed updated versions 18.7.1, 18.6.3, and 18.5.5 to GitLab.com on January 7, 2026, urging self-hosted customers to upgrade immediately.

Zoom released patches addressing the critical networking router vulnerability alongside fixes for denial-of-service flaws. Both companies credited security researchers and internal teams for discovering the vulnerabilities through bug bounty programs.

Anurag Shukla

Anurag Shukla is a Senior Journalist with over two decades of experience across television, digital, and print media. He has worked with leading national news organisations and has also served as a Research Officer in the Prime Minister’s Office (PMO), contributing to media research and policy-level content. A former journalism academic, Anurag brings strong editorial depth and a keen understanding of how technology, governance, and society intersect at Tea4Tech.

Recent Posts

Microsoft Launches its First Cybersecurity AI Model, MAI-Cyber-1-Flash

San Francisco: Microsoft unveiled its first cybersecurity-focused AI model, MAI-Cyber-1-Flash at an event in San…

2 weeks ago

Facebook Blocks PM Modi’s NEET Video, Meta Calls It an Error

New Delhi: The Indian government was caught off guard when social media giant Meta blocked…

2 weeks ago

Moonshot’s Kimi K3 Becomes Largest Open-Weight AI Model Ever

BEIJING: Moonshot AI releases Kimi K3, a 2.8 trillion-parameter model that instantly becomes the largest…

2 weeks ago

Fireworks AI Hits $17.5B as Enterprises Flee Frontier API Prices

SAN MATEO, Calif.: Fireworks AI closes a $1.505 billion Series D at a $17.5 billion…

2 weeks ago

AegisAI Lands $36M Series A to Secure the Agentic Enterprise

SAN FRANCISCO: AegisAI raises $36 million in Series A funding to secure enterprises against threats…

2 weeks ago

Paper Raises $34M as AI Coding Agents Redraw Design’s Borders

SAN FRANCISCO: Paper raises $34 million in Series A funding led by Accel and ICONIQ…

2 weeks ago