< Back to situations

We’ll email you as it develops, and you can follow the whole thread from day one.

[SITUATION] · [ACTIVE]

2 clusters · 9 sources · 19 days · First seen · Last updated

Categories: TECHNOLOGY

Zoom security vulnerabilities and scams

Entities: Securonix · ScreenConnect · Adobe Inc. · Zoom Video Communications, Inc.

Overview

In July 2026 Zoom disclosed a critical remote‑account‑takeover vulnerability (CVE‑2026‑53412) in its Windows client suite and released patches for the affected products, urging immediate installation. Less than a month later, researchers reported a separate threat: a campaign distributing malicious installers masquerading as Zoom (or Adobe) updates. These fake updates install a legitimate ConnectWise ScreenConnect client that gives attackers persistent remote‑desktop access, using various evasion techniques. Together the snapshots show a shift from Zoom addressing its own software flaw to confronting external actors exploiting the Zoom brand to deliver malware.

Timeline

  1. 2 days ago

    [TECHNOLOGY] 9 sources
    Fake Zoom/Adobe Updates Install ScreenConnect Backdoor

    Securonix reports a campaign using fake Zoom and Adobe updates to install the legitimate ScreenConnect client as a backdoor, giving attackers remote access on macOS and Windows via attacker‑controlled relays.

  2. 21 days ago

    [TECHNOLOGY] 5 sources
    Zoom issues critical patch for Windows client vulnerability CVE‑2026‑53412

    Zoom released a patch for a critical Windows client vulnerability (CVE‑2026‑53412) that enables unauthenticated remote account takeover; no exploits reported, users should update immediately.

Sources

dev.to · diariobitcoin.com · gamemag.it · infoguerra.com.br · jamf.com · mactech.com · phonandroid.com · securityaffairs.co · solidsoftwaretools.com