# Zoom security vulnerabilities and scams

> Live situation record from CLSTR: https://clstr.news/situations/zoom-security-vulnerabilities-and-scams
> Updated: 2026-08-04T13:42:36.000Z. Sources: 9. Developments: 2.

In July 2026 Zoom disclosed a critical remote‑account‑takeover vulnerability (CVE‑2026‑53412) in its Windows client suite and released patches for the affected products, urging immediate installation. Less than a month later, researchers reported a separate threat: a campaign distributing malicious installers masquerading as Zoom (or Adobe) updates. These fake updates install a legitimate ConnectWise ScreenConnect client that gives attackers persistent remote‑desktop access, using various evasion techniques. Together the snapshots show a shift from Zoom addressing its own software flaw to confronting external actors exploiting the Zoom brand to deliver malware.

## Timeline

### 2026-08-04: Fake Zoom/Adobe Updates Install ScreenConnect Backdoor

Securonix reports a campaign using fake Zoom and Adobe updates to install the legitimate ScreenConnect client as a backdoor, giving attackers remote access on macOS and Windows via attacker‑controlled relays.

9 sources. https://clstr.news/cluster/fake-zoomadobe-updates-install-screenconnect-backdoor

### 2026-07-16: Zoom issues critical patch for Windows client vulnerability CVE‑2026‑53412

Zoom released a patch for a critical Windows client vulnerability (CVE‑2026‑53412) that enables unauthenticated remote account takeover; no exploits reported, users should update immediately.

5 sources. https://clstr.news/cluster/zoom-releases-patch-for-critical-windows-client-vulnerability-cve202653412

---
Cite as: Zoom security vulnerabilities and scams. CLSTR, https://clstr.news/situations/zoom-security-vulnerabilities-and-scams
