Critical Vulnerabilities Patched in Adobe, Chrome, Firefox, VMware, and Zoom – Immediate Updates Required
What Happened — Adobe, Google Chrome, Mozilla Firefox, VMware (Avi Load Balancer), and Zoom released security updates in July 2026 that address multiple critical flaws, including arbitrary code execution, use‑after‑free bugs, authentication bypasses, and input‑validation errors. Public exploit code is already known for at least two of the browser issues.
Why It Matters for Compliance & Audit Readiness —
- Unpatched software directly violates SOC 2 CC6.1 (Change Management) and CC7.1 (System Operations) requirements to remediate known vulnerabilities in a timely manner.
- Demonstrating continuous patch‑management evidence is a core audit artifact; failure to do so can be cited as a control gap during a SOC 2 examination.
- Verisq’s Control Mapping capability helps you map each vendor patch to the relevant SOC 2 control, collect automated proof of update status, and keep a defensible audit trail.
Who Is Affected — Enterprises of all sizes, SaaS providers, MSPs, and small‑business users that run any of the listed products.
Recommended Actions —
- Inventory all instances of Adobe ColdFusion, Chrome, Firefox, VMware Avi Load Balancer, and Zoom Workplace across your environment.
- Apply the vendor patches immediately, restart services where required, and verify version numbers.
- Record the patch‑application in your change‑management system and map it to SOC 2 CC6.1/CC7.1 controls using a continuous‑evidence platform.
Source: Malwarebytes Labs – Security updates available for Adobe, Chrome, Firefox, VMWare, and Zoom
Technical Notes —
- Adobe ColdFusion: multiple critical RCE flaws (no CVE IDs disclosed).
- Chrome 150.0.7871.124/.125: 15 bugs, two critical use‑after‑free (Ozone).
- Firefox 152.0.6: two critical bugs with public exploit code (JavaScript/WebAssembly and DOM navigation).
- VMware Avi Load Balancer: CVE‑2026‑47865, authentication bypass to control plane.
- Zoom Workplace for Windows: CVE‑2026‑53412, improper input validation.
Source: same as above