news.mlab.sh
Back to the feed
vulnerability

Splunk, Zoom Patch Critical Vulnerabilities

High
Summary

Splunk and Zoom have released patches to address several critical and high-severity vulnerabilities in their respective products. These flaws could allow attackers to steal credentials, access sensitive data, and potentially take over accounts. Both companies are urging users to update immediately to mitigate these risks.

Splunk and Zoom announced security updates this week to address a range of vulnerabilities affecting their software. The updates are crucial for maintaining system security and preventing potential breaches. Splunk published five advisories, with three directly targeting their products and two addressing issues within third-party components. These Splunk-specific vulnerabilities include CVE-2026-20296 (a high-severity command safeguards bypass), CVE-2026-20297 (a high-severity path traversal), and CVE-2026-20298 (a medium-severity information disclosure). Successful exploitation of these weaknesses could lead to unauthorized access to credentials and data, as well as the ability to write files outside the intended application directory and view stored credential hashes. Zoom, on the other hand, released four advisories focused on their Windows clients and tools. The most severe vulnerability, CVE-2026-53412 (CVSS score of 9.8), is a critical bug in Zoom’s Workplace and Workplace VDI Client for Windows, allowing unauthenticated remote attackers to mount account takeover attacks. Zoom’s updates also address three high-severity flaws, including a time-of-check-to-time-of-use (TOCTOU) race condition and two privilege elevation issues. Neither Splunk nor Zoom have indicated that these vulnerabilities have been actively exploited. The updates are available for Splunk Enterprise versions 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and for Zoom’s Windows clients.

Read the full article at SecurityWeek