Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Vulnerabilities Patched by Splunk and Zoom

Critical Vulnerabilities Patched by Splunk and Zoom

Posted on March 12, 2026 By CWS

Splunk and Zoom Implement Vital Security Updates

This week, Splunk and Zoom have released crucial security updates to address multiple critical and high-severity vulnerabilities within their product lines. These updates are essential for maintaining the security and integrity of their software.

Zoom’s Critical Vulnerability Fixes

Zoom has tackled a critical flaw within its Workplace for Windows application, which posed a risk by allowing unauthenticated, remote attackers to gain elevated privileges over the network. This security issue, affecting the Mail feature, has been resolved in the latest version 6.6.0 for Workplace for Windows and versions 6.4.17, 6.5.15, and 6.6.10 for the Workplace VDI Client.

Besides this, Zoom has also released patches for three high-severity vulnerabilities in specific Windows Zoom Clients. These vulnerabilities could have allowed local attackers to increase their privileges, posing significant security threats.

Splunk’s Comprehensive Update Rollout

On Wednesday, Splunk issued a new series of updates for Splunk Enterprise, addressing numerous vulnerabilities, including five specific to their products. The most serious of these, labeled CVE-2026-20163, has a CVSS score of 8.0. This high-severity flaw could be exploited by attackers with high privileges to execute arbitrary shell commands via a REST endpoint.

The issue was rooted in inadequate input sanitization during the preview of uploaded files before indexing. The patch was implemented in Splunk Enterprise versions 10.2.0, 10.0.4, 9.4.9, and 9.3.10. These updates also fix three medium-severity vulnerabilities that could lead to XSS attacks, credential leaks, and exposure of sensitive data.

Third-Party Dependency Updates and Future Security

In addition to the primary updates, Splunk has also addressed numerous CVEs in third-party packages used by Splunk Enterprise, including several Golang dependencies. A medium-severity vulnerability that risked leaking Observability Cloud API access tokens was resolved in versions 10.2.1 and 10.0.4.

Furthermore, Splunk has fixed multiple critical vulnerabilities in third-party packages within Splunk AppDynamics. Although the company has not reported any active exploitation of these vulnerabilities, users are encouraged to update their systems promptly. Detailed information about these updates is available on Splunk’s security advisories page.

Keeping software up-to-date is crucial in the ongoing battle against cyber threats. As new vulnerabilities emerge, timely updates ensure that systems remain protected against potential exploits.

Security Week News Tags:cyber threats, Cybersecurity, IT security, network security, Patches, security updates, software updates, Splunk, Splunk Enterprise, Vulnerabilities, Windows security, Zoom, Zoom Workplace

Post navigation

Previous Post: MediaTek Chip Flaw Exposes Android PINs in Seconds
Next Post: Microsoft OAuth Device Phishing Threat Escalates

Related Posts

Akira Ransomware’s Exploitation of SonicWall Vulnerability Continues Akira Ransomware’s Exploitation of SonicWall Vulnerability Continues Security Week News
Microsoft Unveils Security Enhancements for Identity, Defense, Compliance Microsoft Unveils Security Enhancements for Identity, Defense, Compliance Security Week News
European Space Agency Confirms Breach After Hacker Offers to Sell Data European Space Agency Confirms Breach After Hacker Offers to Sell Data Security Week News
SquareX and Perplexity Quarrel Over Alleged Comet Browser Vulnerability SquareX and Perplexity Quarrel Over Alleged Comet Browser Vulnerability Security Week News
ThreatSpike Raises  Million in Series A Funding ThreatSpike Raises $14 Million in Series A Funding Security Week News
Massive Data Breach at ApolloMD Affects Over 626,000 Massive Data Breach at ApolloMD Affects Over 626,000 Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Cyber Threats: Exploits, Malware, and Global Crackdown
  • Trojan VPNs Spread via SEO Poisoning, Microsoft Warns
  • Metasploit Pro 5.0.0 Launches with Enhanced Security Features
  • Iran-Affiliated Cyberattack Disrupts Stryker’s Operations
  • New ClickFix Variant Exploits Network Drives

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Cyber Threats: Exploits, Malware, and Global Crackdown
  • Trojan VPNs Spread via SEO Poisoning, Microsoft Warns
  • Metasploit Pro 5.0.0 Launches with Enhanced Security Features
  • Iran-Affiliated Cyberattack Disrupts Stryker’s Operations
  • New ClickFix Variant Exploits Network Drives

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News