Zoom issues critical patch for Windows client vulnerability CVE‑2026‑53412
Zoom has classified a critical vulnerability (CVE‑2026‑53412) in its Windows client suite—including Zoom Workplace, Meeting SDK and VDI client—as capable of remote account takeover without any authentication, password, or user interaction. The flaw, rated 9.8 on the CVSS scale, stems from inadequate input validation and can be exploited over the network. Zoom disclosed no evidence of active exploitation and released patches that update the affected products to the latest versions (Zoom Workplace ≥ 7.0.0, Meeting SDK ≥ 7.0.0, VDI client releases 7.0.10, 6.6.15, 6.5.18). The same update cycle also addresses three additional high‑severity issues (CVE‑2026‑53410, ‑53409, ‑53411) that require a locally authenticated user and involve privilege escalation.
Zoom recommends that all users and organizations install the new releases immediately via the official portal to mitigate the risk, as no alternative mitigations were disclosed.