A critical vulnerability was discovered and fixed in the Zcash Orchard privacy pool by researcher Taylor Hornby. This vulnerability, if exploited, could have allowed attackers to generate ZEC fraudulently. The issue was due to a validation check not enforcing its intended rules.