Splunk and Zoom release security patches for critical vulnerabilities
Splunk, Zoom, and several major web browsers have issued urgent security updates to address critical vulnerabilities, including some with public exploit code.
As of Thursday, 16 July 2026, technology administrators and individual users are facing a widespread mandate for software updates. Following a series of coordinated and independent disclosures from major software vendors, critical vulnerabilities have been identified across platforms ranging from enterprise collaboration tools like Splunk and Zoom to core web infrastructure including Adobe, Chrome, Firefox, and VMware.
The urgency stems from the severity of the flaws. While vendors have reported no evidence of active exploitation in the wild for several of these specific bugs, the confirmed availability of public exploit code for certain browser-based vulnerabilities has intensified the pressure on organizations to patch immediately.
Related imagery
Browser Security: A Complex Patch Landscape
The web browser remains the primary attack surface for most digital environments. Google recently deployed updates for Chrome to versions 150.0.7871.124/.125, which resolve 15 security flaws, including two critical use-after-free bugs in Ozone.
Mozilla has similarly released critical updates for Firefox, specifically version 152.0.6. This release addresses two flaws that involve JavaScript/WebAssembly processing and DOM navigation. Notably, Mozilla confirmed that public exploit code exists for both issues, a detail that shifts the status of these bugs from theoretical threats to immediate operational risks.
Enterprise Tools and Infrastructure
Beyond the browser, specialized enterprise software has also received critical patches. Splunk, a major provider of security and observability software, released updates to address vulnerabilities specific to its platform, including a high-severity command safeguards bypass and a path traversal issue. These updates—applied to Splunk Enterprise versions 10.4.1, 10.2.5, 10.0.8, and 9.4.13—also bundle fixes for critical vulnerabilities within third-party components like Golang and OpenSSL. The Splunk-specific issues include CVE-2026-20296, CVE-2026-20297, and CVE-2026-20298.
Zoom has issued its own security bulletin, ZSB-26014, to address a critical bug in Zoom Workplace and the Workplace VDI Client for Windows. Tracked as CVE-2026-53412, the vulnerability carries a CVSS score of 9.8 and could allow an unauthenticated attacker to take over a user's account. Additionally, Broadcom has patched a critical authentication bypass in the VMware Avi Load Balancer, tracked as CVE-2026-47865, which could allow a network-accessible attacker to reach the Avi Control Plane.
Recommended Mitigation Checklist
- Verify Versions: Manually check the "About" section of your browser to ensure you are running the latest patched release.
- Prioritize Enterprise Deployments: For organizations, ensure that centralized deployment packages are updated. Old, vulnerable builds frequently persist in deployment caches, leading to re-infection cycles.
- Restart Immediately: Many of these patches do not fully take effect until the application is restarted. Simply downloading the update is insufficient for full protection.
- Monitor Logs: For security teams, monitor web proxy and SIEM logs for unusual JavaScript patterns or WebAssembly loading behaviors, which may indicate attempted exploitation of these browser-based flaws.
- Deployment Verification: For enterprise fleets, use management tools like the Google Admin Console or SCCM/Jamf Pro to force updates and verify compliance across managed devices.
What to Watch Next
While the immediate focus is on patching, experts suggest that the coming weeks will likely see increased activity as threat actors attempt to reverse-engineer the recently released security patches. Organizations are advised to monitor the CISA Known Exploited Vulnerabilities catalog for any updates regarding active weaponization of these specific CVEs. Because threat actors have been observed chaining memory corruption bugs with privilege escalation flaws to bypass browser sandboxes, security teams are encouraged to maintain heightened monitoring for suspicious process spawning and lateral movement attempts within their networks.
Transparency record
Evidence behind this report
This report synthesizes 10 distinct sources. Open the source ledger below to compare the underlying coverage.
- aviatrix.ai
- securityweek.com
- malwarebytes.com
- forbes.com
- linkedin.com
- sparknherd.com
- anavem.com
- cvefeed.io
- cyberwebspider.com
- ca.news.yahoo.com
Prepared under the Archypedia Editorial Policy by the Niko Vale editorial desk profile. AI-assisted tools may support drafting and verification; public accountability remains with Archypedia. Report an error.