Zoom says a critical flaw in its Windows desktop client and related software could let an unauthenticated attacker hijack user accounts over the network. The issue, CVE-2026-53412, is rated 9.8/10 and affects Zoom Workplace for Windows before 7.0.0, the Windows VDI client before 7.0.10, 6.6.15, and 6.5.18, and the Meeting SDK for Windows before 7.0.0. Zoom described it as improper input validation and said users should install the latest updates; no in-the-wild exploitation was reported at disclosure.
Why it matters: Zoom is used by millions of people and organizations, so a network-reachable account-takeover flaw is high impact even without confirmed active attacks. Organizations and individual users running affected Windows versions should update immediately and review where Zoom Workplace, VDI deployments, or the Meeting SDK are installed.
Ionut Arghire
2026.07.16
93% relevant
This article reports Zoom's advisory and adds that CVE-2026-53412 affects Zoom Workplace and Workplace VDI Client for Windows, is rated 9.8, and was patched alongside a TOCTOU race condition and two privilege-escalation flaws, with no evidence of in-the-wild exploitation mentioned.
info@thehackernews.com (The Hacker News)
2026.07.16
98% relevant
This appears to be the patch/update coverage for the same Zoom Windows account-takeover flaw, adding that fixes are now available rather than just warning that the vulnerability exists.
Bill Toulas
2026.07.15
100% relevant
This article appears to be the first tracked report of Zoom's advisory for CVE-2026-53412 and establishes the underlying event: a critical Windows account-takeover vulnerability requiring immediate updates.
← Back to all stories