HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

Critical Vulnerabilities Patched in Adobe, Chrome, Firefox, VMware, and Zoom – Immediate Updates Required

Adobe, Chrome, Firefox, VMware, and Zoom released patches for critical flaws that could lead to code execution or privilege escalation. For SOC 2‑compliant organizations, timely patching is essential to satisfy change‑management and system‑operations controls.

LiveThreat™ Intelligence · 📅 July 16, 2026· 📰 malwarebytes.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
malwarebytes.com

Critical Vulnerabilities Patched in Adobe, Chrome, Firefox, VMware, and Zoom – Immediate Updates Required

What Happened — Adobe, Google Chrome, Mozilla Firefox, VMware (Avi Load Balancer), and Zoom released security updates in July 2026 that address multiple critical flaws, including arbitrary code execution, use‑after‑free bugs, authentication bypasses, and input‑validation errors. Public exploit code is already known for at least two of the browser issues.

Why It Matters for Compliance & Audit Readiness

  • Unpatched software directly violates SOC 2 CC6.1 (Change Management) and CC7.1 (System Operations) requirements to remediate known vulnerabilities in a timely manner.
  • Demonstrating continuous patch‑management evidence is a core audit artifact; failure to do so can be cited as a control gap during a SOC 2 examination.
  • Verisq’s Control Mapping capability helps you map each vendor patch to the relevant SOC 2 control, collect automated proof of update status, and keep a defensible audit trail.

Who Is Affected — Enterprises of all sizes, SaaS providers, MSPs, and small‑business users that run any of the listed products.

Recommended Actions

  • Inventory all instances of Adobe ColdFusion, Chrome, Firefox, VMware Avi Load Balancer, and Zoom Workplace across your environment.
  • Apply the vendor patches immediately, restart services where required, and verify version numbers.
  • Record the patch‑application in your change‑management system and map it to SOC 2 CC6.1/CC7.1 controls using a continuous‑evidence platform.

Source: Malwarebytes Labs – Security updates available for Adobe, Chrome, Firefox, VMWare, and Zoom

Technical Notes

  • Adobe ColdFusion: multiple critical RCE flaws (no CVE IDs disclosed).
  • Chrome 150.0.7871.124/.125: 15 bugs, two critical use‑after‑free (Ozone).
  • Firefox 152.0.6: two critical bugs with public exploit code (JavaScript/WebAssembly and DOM navigation).
  • VMware Avi Load Balancer: CVE‑2026‑47865, authentication bypass to control plane.
  • Zoom Workplace for Windows: CVE‑2026‑53412, improper input validation.

Source: same as above

📰 Original Source
https://www.malwarebytes.com/blog/bugs/2026/07/security-updates-available-for-adobe-chrome-firefox-vmware-and-zoom

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →