Splunk, Zoom Patch Severe Vulnerabilities
securityweekCritical- and high-severity flaws could be exploited to execute arbitrary shell commands or elevate privileges.


Splunk and Zoom this week announced security updates that resolve multiple critical- and high-severity vulnerabilities across their product portfolios.
Zoom has addressed a critical-severity flaw in Workplace for Windows that could allow unauthenticated, remote attackers to elevate their privileges over the network.
The issue impacts the Mail feature of the product and was addressed in Workplace for Windows version 6.6.0 and Workplace VDI Client for Windows versions 6.4.17, 6.5.15, and 6.6.10.
Additionally, Zoom rolled out patches for three high-severity security defects in certain Zoom Clients for Windows that could be exploited by local attackers to escalate their privileges.
Splunk on Wednesday released a fresh round of Splunk Enterprise updates that resolve dozens of issues, including five that are product-specific.
The most severe of these bugs is CVE-2026-20163 ...
Copyright of this story solely belongs to securityweek . To see the full text click HERE

