Zoom account takeover, Splunk credential exposure

The weak point is broader than one vendor alert. Zoom’s Windows flaw can let a remote, unauthenticated attacker take over an account, and Splunk’s fixes cover bugs that can expose stored credentials and hashes or let files land outside the app’s own directory. Patching the product is not the whole response when one side can hand over account control and the other can hand over secrets for follow-on access. Zoom says CVE-2026-53412 affects Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows. Splunk’s product-specific CVE-2026-20296, CVE-2026-20297, and CVE-2026-20298 cover a command safeguards bypass, path traversal, and information disclosure, with fixes in Splunk Enterprise 10.4.1, 10.2.5, 10.0.8, and 9.4.13. Neither vendor says these flaws are being exploited in the wild. The remaining risk is what those products already stored or brokered before patching. If Zoom or Splunk sits in a login, management, or embedded SDK path, the exposed account or secret can outlive the patch.

Part of the PlainSec briefing for 2026-07-18

Sources