Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Splunk, Zoom Patch Severe Vulnerabilities

Critical- and high-severity flaws could be exploited to execute arbitrary shell commands or elevate privileges.

Splunk vulnerability patches

Splunk and Zoom this week announced security updates that resolve multiple critical- and high-severity vulnerabilities across their product portfolios.

Zoom has addressed a critical-severity flaw in Workplace for Windows that could allow unauthenticated, remote attackers to elevate their privileges over the network.

The issue impacts the Mail feature of the product and was addressed in Workplace for Windows version 6.6.0 and Workplace VDI Client for Windows versions 6.4.17, 6.5.15, and 6.6.10.

Additionally, Zoom rolled out patches for three high-severity security defects in certain Zoom Clients for Windows that could be exploited by local attackers to escalate their privileges.

Splunk on Wednesday released a fresh round of Splunk Enterprise updates that resolve dozens of issues, including five that are product-specific.

The most severe of these bugs is CVE-2026-20163 (CVSS score of 8.0), a high-severity flaw that could be exploited by attackers who already have high privileges on a vulnerable deployment to execute arbitrary shell commands through a REST endpoint.

Advertisement. Scroll to continue reading.

“This occurs because of insufficient input sanitization when previewing uploaded files before indexing them,” Splunk says.

The security defect was addressed in Splunk Enterprise versions 10.2.0, 10.0.4, 9.4.9, and 9.3.10, which also resolve three medium-severity flaws leading to XSS attacks, credential exposure, and sensitive information disclosure.

The updates also include fixes for dozens of CVEs in third-party packages used in Splunk Enterprise, including multiple Golang dependencies.

A fourth medium-severity issue that could lead to Observability Cloud API access token leakage was resolved in Splunk Enterprise versions 10.2.1 and 10.0.4.

Additionally, Splunk rolled out fixes for dozens of other vulnerabilities in third-party packages in Splunk AppDynamics, including multiple critical-severity flaws.

Splunk made no mention of any of these security defects being exploited in the wild. Additional information can be found on the company’s security advisories page.

Related: Cisco Patches High-Severity IOS XR Vulnerabilities

Related: Critical N8n Vulnerabilities Allowed Server Takeover

Related: Fortinet, Ivanti, Intel Patch High-Severity Vulnerabilities

Related: ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Moxa, Mitsubishi Electric

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Stephen Garcia has been named Chief Information Security Officer at BreachRx.

Kasper Lindgaard has been appointed Vice President of Security Strategy at CoreView.

Chaim Mazal has been named Chief Information Security Officer at GitLab.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.