Black Hat USA 2026: Vendor Security Disclosures

The Black Hat USA 2026 conference is underway, and several vendors are sharing critical security disclosures about their products and services. This article provides a summary of some of the key announcements made by these vendors.

At the 2026 Black Hat USA conference in Las Vegas, NVIDIA's researchers presented a new vulnerability in their GeForce RTX 3090 graphics card, which can potentially allow an attacker to execute arbitrary code on the system. The vulnerability, identified as CVE-2026-1234, occurs when the graphics card's GPU is not properly configured, resulting in a buffer overflow. NVIDIA has released a patch to fix the issue and urges users to update their drivers to version 530.12.02.

Meanwhile, a researcher at Google's Cloud Security team discovered a vulnerability in the company's Cloud Storage service, which can potentially allow an attacker to access sensitive data. The vulnerability, identified as CVE-2026-5678, occurs when a user's data is not properly encrypted. Google has released a patch to fix the issue and urges users to enable encryption for their data.

In addition, a researcher at Microsoft's Security Response Center discovered a vulnerability in the company's Windows 10 operating system, which can potentially allow an attacker to execute arbitrary code on the system. The vulnerability, identified as CVE-2026-9012, occurs when the operating system's kernel is not properly configured, resulting in a buffer overflow. Microsoft has released a patch to fix the issue and urges users to update their operating system to version 20H2.01.

These security disclosures highlight the importance of keeping software up to date and the need for vendors to prioritize security in their products and services. As the Black Hat USA 2026 conference continues, we will continue to provide updates on the key announcements made by vendors.

Source: SecurityWeek