CVE-2025-24924: Gmod Apollo

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Certain functionality within GMOD Apollo does not require authentication when passed with an administrative username

Affected products

  • Gmod Apollo: before 2.8.0 (fixed in 2.8.0)

Published 2025-03-05. Last modified 2026-06-17.