
CVE-2026-20296,20297,20298,53412: Splunk & Zoom — Credential Theft, Account Takeover Risk (June 2026)
CVE-2026-20296,20297,20298,53412 — Splunk & Zoom
Multiple critical vulnerabilities (CVE-2026-20296, CVE-2026-20297, CVE-2026-20298, CVE-2026-53412) have been identified in Splunk Enterprise and Zoom Windows clients. These flaws allow attackers to steal credentials, escalate privileges, take over accounts, and write unauthorized files. All are rated critical; exploitation could result in full compromise of affected systems. No evidence of active exploitation has been reported yet, but public disclosure increases risk.
Attack Vector
Attackers can exploit these vulnerabilities via crafted requests targeting core application components and third-party libraries. Successful exploitation may require network access to the affected service or user interaction (e.g., opening a malicious file or link). Attackers can leverage these flaws to extract credentials, escalate privileges, and gain unauthorized file system access. No specific IOCs have been published, but organizations should monitor for anomalous authentication attempts and unexpected file writes.
Who Is at Risk
Splunk Enterprise (multiple versions) and Zoom Windows client deployments are affected globally. Organizations using unpatched Splunk or Zoom installations are at immediate risk, especially those with internet-exposed instances or large user bases. Both vendors have confirmed the impact and released security updates.
Patch & Mitigate
- Patch: Apply the latest Splunk Enterprise and Zoom Windows client security updates released June 2026. Check vendor advisories for exact version numbers and upgrade instructions.
- Workaround: No official workarounds are available; patching is mandatory.
- Detect: Review authentication logs for unusual login attempts, privilege escalation events, and unauthorized file creation or modification. Monitor for suspicious outbound connections from Splunk or Zoom processes.
MITRE ATT&CK
- TA0006 — Credential Access: Attackers can steal credentials via exploitation of application flaws.
- TA0007 — Privilege Escalation: Vulnerabilities enable attackers to elevate privileges and gain broader access.
Source: https://www.securityweek.com/splunk-zoom-patch-critical-vulnerabilities/
Start Your 14-Day Free Trial
Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.
Get Started Free

