Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Anduril has invented a novel drone flying contest where work is the prize

Bluesky previews 2026 roadmap: Discover feed, real-time features, and more improvements

Anthropic and OpenAI CEOs condemn ICE violence, praise Trump

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Zoom and GitLab release security updates that fix RCE, DoS, and 2FA bypass flaws
Identity

Zoom and GitLab release security updates that fix RCE, DoS, and 2FA bypass flaws

userBy userJanuary 21, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Rabi LakshmananJanuary 21, 2026Vulnerability/Network Security

Zoom and GitLab have released security updates that resolve a number of security vulnerabilities that could lead to a denial of service (DoS) or remote code execution.

The most serious issue is a critical security flaw affecting the Zoom Node Multimedia Router (MMR) that could allow meeting participants to conduct remote code execution attacks. The vulnerability, tracked as CVE-2026-22844, was discovered internally by the Attack Security team and had a CVSS score of 9.9 out of 10.0.

“A command injection vulnerability in the Zoom Node Multimedia Router (MMR) prior to version 5.2.1716.0 could allow a meeting participant to perform remote code execution of the MMR via network access,” the company noted in a Tuesday alert.

Zoom recommends that customers using Zoom Node Meetings, Hybrid, or Meeting Connector deployments update to the latest available MMR version to protect against potential threats.

There is no evidence that this security flaw has been exploited in the wild. This vulnerability affects the following versions:

Zoom Node Meetings Hybrid (ZMH) MMR module versions earlier than 5.2.1716.0 Zoom Node Meeting Connector (MC) MMR module versions earlier than 5.2.1716.0

cyber security

GitLab releases patch for critical flaw

This disclosure comes as GitLab releases fixes for multiple high-severity flaws affecting Community Edition (CE) and Enterprise Edition (EE) that could lead to DoS or bypassing two-factor authentication (2FA) protections. The disadvantages are:

CVE-2025-13927 (CVSS score: 7.5) – Vulnerability that allows an unauthenticated user to cause a DoS condition by sending a crafted request that contains malformed authentication data in 18.6.4 before 11.9, 18.7 before 18.7.2, and 18.8.2 before 18.8. CVE-2025-13928 (CVSS score: 7.5) – An incorrect authentication vulnerability in the release API allows an unauthenticated user to cause a DoS condition (17.7 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2) CVE-2026-0723 (CVSS score: 7.4) – Vulnerability that allows an individual with existing knowledge of the victim’s credential identity to bypass 2FA by sending a forged device response (18.6.4 before 18.6, 18.7 before 18.7.2, and 18.8.2 before (affects all versions of 18.8)

GitLab also fixed two other medium-severity bugs that could cause a DoS condition (CVE-2025-13335, CVSS score: 6.5, and CVE-2026-1102, CVSS score: 5.3) by setting a malformed Wiki document that bypasses cycle detection and repeatedly sending malformed SSH authentication requests.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleOpenAI aims to ship first device in 2026, and it could be earphones
Next Article The 2.6 million-year-old jaw of the extinct ‘Nutcracker Man’ is discovered in an unexpected location
user
  • Website

Related Posts

WhatsApp deploys lockdown-style security mode to protect targeted users from spyware

January 27, 2026

Experts detect Pakistan-linked cyber attack targeting Indian government agencies

January 27, 2026

ClickFix attack spreads using fake CAPTCHAs, Microsoft Scripts, and trusted web services

January 27, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Anduril has invented a novel drone flying contest where work is the prize

Bluesky previews 2026 roadmap: Discover feed, real-time features, and more improvements

Anthropic and OpenAI CEOs condemn ICE violence, praise Trump

Android smartphones are getting more anti-theft features

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.