Security News

Cybersecurity news aggregator

🔄
CRITICAL Updates SecurityWeek

Splunk, Zoom Patch Critical Vulnerabilities

Splunk has patched three product-specific vulnerabilities: CVE-2026-20296 (CVSS 8.3), a command safeguards bypass; CVE-2026-20297 (CVSS 7.2), a path traversal flaw; and CVE-2026-20298 (CVSS 5.3), an information disclosure issue. These flaws could allow credential and data access, arbitrary file writes, and hash disclosure. Patches are included in Splunk Enterprise versions 10.4.1, 10.2.5, 10.0.8, and 9.4.13, which also address critical third-party library vulnerabilities.
Read Full Article →

Vulnerabilities Splunk, Zoom Patch Critical Vulnerabilities The flaws could allow attackers to access credentials and data, take over accounts, and escalate their privileges. By Ionut Arghire | July 16, 2026 (6:54 AM ET) Flipboard Reddit Whatsapp Whatsapp Email Splunk and Zoom this week announced patches for multiple vulnerabilities across their products, including several critical and high-severity security defects. Only three of the five advisories that Splunk published address flaws that are specific to its products, while the other two resolve dozens of bugs in third-party components. The Splunk-specific issues include CVE-2026-20296 (a high-severity command safeguards bypass), CVE-2026-20297 (a high-severity path traversal), and CVE-2026-20298 (a medium-severity information disclosure). Successful exploitation of these weaknesses could allow attackers to access credentials and data, write files outside the intended application directory, and view stored credential hashes. Patches for all three were included in Splunk Enterprise versions 10.4.1, 10.2.5, 10.0.8, and 9.4.13, which also address critical- and high-severity vulnerabilities in Golang, Go compiler, OpenSSL, and other third-party libraries. Zoom published four advisories that resolve as many vulnerabilities across its clients and tools for Windows. Advertisement. Scroll to continue reading. The most severe is CVE-2026-53412 (CVSS score of 9.8), a critical bug in Zoom’s Workplace and Workplace VDI Client for Windows that could allow remote, unauthenticated attackers to mount account takeover attacks. The company’s updates also resolve three high-severity flaws: a time-of-check-to-time-of-use (TOCTOU) race condition and two privilege elevation issues. Neither Splunk nor Zoom makes any mention of these vulnerabilities being exploited in the wild. Related: F5 Patches Multiple NGINX, BIG-IP Vulnerabilities Related: Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day Related: Old UEFI Shims Expose Systems to Secure Boot Bypass Related: CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow Progress Confirms Zero-Day Vulnerability Behind ShareFile Disruption Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days Adobe Patches Critical ColdFusion Vulnerabilities SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud US, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers Multiple Jscrambler Packages Impacted by Supply Chain Attack Latest News F5 Patches Multiple NGINX, BIG-IP Vulnerabilities China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans Old UEFI Shims Expose Systems to Secure Boot Bypass Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities Unpatched Cursor Vulnerability Exposes Users to Code Execution CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities Windows Bind Link Attacks Can Hide Malware From EDR Tools Trending Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Why Email Security Keeps Failing (And What Has to Change) July 8, 2026 Join this live webinar as we break down why email-layer defenses alone can't keep pace with the modern phishing ecosystem, how agentic AI is changing the capacity equation for security teams, and more. Register Virtual Event: 2026 Cloud Security Summit July 15, 2026 This year's summit will help organizations learn how to utilize tools, controls, and design models needed to properly secure cloud environments. Interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments. Register People on the Move N-able has appointed Russell Rosa as Chief Revenue Officer. Stacy O'Mara has joined Armadin as Chief Policy Officer and Director of Global Government Affairs. F5 has appointed Cathy Peterman as Chief People Officer. More People On The Move Expert Insights The Shift Toward Business-Aligned Risk Management Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. (Steve Durbin) How to Conduct a Successful Audit of AI-Driven Software Development As AI-generated code becomes commonplace, CISOs need new audit strategies to measure developer practices, govern AI tool usage, and identify software risks before they reach production. (Matias Madou) Frontier AI: Six Questions Every Enterprise Should Ask Security Vendors From model selection and automation to validation and measurable results, the right questions can help enterprises separate genuine AI capabilities from marketing hype. (Joshua Goldfarb) The AI Token Costs That Can Break Cybersecurity As cybersecurity platforms embrace agentic AI, organizations must balance detection performance against the escalating costs of token consumption, deployment architecture, and AI credits. (Danelle Au) When Information Becomes the Attack Surface – Understanding AI Agent Traps From hidden content injections to cognitive state poisoning, attackers are turning trusted data sources into traps for autonomous AI. (Etay Maor) Flipboard Reddit Whatsapp Whatsapp Email

Share this article