Zoom warns of critical Windows flaw CVE-2026-53412 that could let attackers take over accounts

Zoom says a critical flaw in its Windows desktop client and related software could let an unauthenticated attacker hijack user accounts over the network. The issue, CVE-2026-53412, is rated 9.8/10 and affects Zoom Workplace for Windows before 7.0.0, the Windows VDI client before 7.0.10, 6.6.15, and 6.5.18, and the Meeting SDK for Windows before 7.0.0. Zoom described it as improper input validation and said users should install the latest updates; no in-the-wild exploitation was reported at disclosure.
Why it matters: Zoom is used by millions of people and organizations, so a network-reachable account-takeover flaw is high impact even without confirmed active attacks. Organizations and individual users running affected Windows versions should update immediately and review where Zoom Workplace, VDI deployments, or the Meeting SDK are installed.

Sources

Splunk, Zoom Patch Critical Vulnerabilities
Ionut Arghire 2026.07.16 93% relevant
This article reports Zoom's advisory and adds that CVE-2026-53412 affects Zoom Workplace and Workplace VDI Client for Windows, is rated 9.8, and was patched alongside a TOCTOU race condition and two privilege-escalation flaws, with no evidence of in-the-wild exploitation mentioned.
Zoom Patches Critical Windows Flaw That Could Enable Account Takeover
info@thehackernews.com (The Hacker News) 2026.07.16 98% relevant
This appears to be the patch/update coverage for the same Zoom Windows account-takeover flaw, adding that fixes are now available rather than just warning that the vulnerability exists.
Zoom warns of critical account takeover vulnerability
Bill Toulas 2026.07.15 100% relevant
This article appears to be the first tracked report of Zoom's advisory for CVE-2026-53412 and establishes the underlying event: a critical Windows account-takeover vulnerability requiring immediate updates.
← Back to all stories