
SANS StormCast Highlights Critical Vulnerabilities and Patches in Apple, VMware, and OpenWRT
The July 30, 2026, SANS Internet Storm Center StormCast covered multiple critical vulnerabilities. Apple released patches for three CVEs addressing maliciously crafted ZIP archives that could bypass Gatekeeper, though security researchers at MISC noted their disclosed TAR archive vulnerability remained unpatched. A separate MISC-reported flaw allowing websites to access clipboard data was fixed. Researchers from Lava HQ revealed a 20-year-old IPMI authentication protocol vulnerability where UDP port 623 could expose HMAC-SHA1 hashes of admin passwords, with 30% of scanned passwords recoverable. VMware issued updates for vCenter, including a directory traversal in syslog (CVE unspecified) and an authentication bypass leading to remote code execution. OpenWRT released fixes for a buffer overflow in its ODHCP DHCPv6 server (CVSS 9.8), affecting devices like GL.iNet routers. The episode emphasized restricting control plane access, such as IPMI and vCenter admin interfaces, from public exposure.