Splunk and Zoom release patches for critical security flaws

Splunk and Zoom released updates this week to fix multiple critical and high‑severity vulnerabilities, including three Splunk CVEs and Zoom’s CVE‑2026‑53412 Windows account‑takeover bug.

Splunk and Zoom released security updates this week that address multiple critical and high‑severity vulnerabilities across their products. The updates include three product‑specific Splunk CVEs and a critical Windows bug in Zoom tracked as CVE‑2026‑53412.

Splunk published five advisories. Three address defects in Splunk software: CVE‑2026‑20296, a high‑severity bypass of command safeguards; CVE‑2026‑20297, a high‑severity path traversal that can allow files to be written outside the intended application directory; and CVE‑2026‑20298, a medium‑severity information disclosure that may expose stored credential hashes. Fixes for these issues are included in Splunk Enterprise 10.4.1, 10.2.5, 10.0.8 and 9.4.13. The listed Enterprise releases also remediate critical and high‑severity vulnerabilities in bundled third‑party components such as Golang, the Go compiler and OpenSSL.

Zoom posted four advisories covering vulnerabilities in its Windows clients and related tools. The most severe is CVE‑2026‑53412, rated 9.8 under CVSS, which affects Zoom Workplace and the Workplace VDI Client for Windows and can allow a remote, unauthenticated attacker to take over an account. The updates also address a time‑of‑check‑to‑time‑of‑use (TOCTOU) race condition and two issues that could lead to privilege elevation.

Organizations using Splunk Enterprise or Zoom Workplace on Windows should check installed version numbers and apply the supplied patches. Splunk administrators should upgrade to one of the fixed Enterprise releases listed by the vendor. Zoom customers should install the updated Windows client and VDI builds that include the CVE‑2026‑53412 fix and the other high‑severity corrections.

Neither Splunk nor Zoom reported active exploitation of the disclosed vulnerabilities at the time of the advisories. Splunk’s advisories include a large set of fixes for bundled third‑party libraries in addition to the product‑specific patches.

Articles by this author