Zoom has issued a security advisory warning users of a critical vulnerability affecting several of its Windows-based products. The flaw, identified as CVE-2026-53412, carries a severity rating of 9.8 out of 10 and could potentially allow a remote, unauthenticated attacker to take over user accounts.
According to Zoom, the vulnerability impacts:
- Zoom Workplace for Windows versions earlier than 7.0.0
- Zoom VDI Client for Windows versions prior to 7.0.10, 6.6.15, and 6.5.18
- Zoom Meeting SDK for Windows versions earlier than 7.0.0
The issue was discovered internally by Zoom and has been classified as an improper input validation vulnerability. While the company has not released technical details, it confirmed that a successful exploit could enable account takeover through network access without requiring user authentication.
Zoom Workplace, formerly known simply as Zoom, is widely used by businesses and individuals for video conferencing, chat, VoIP calling, email, calendars, document collaboration, whiteboarding, and AI-powered productivity tools. Given the platform’s broad adoption, organizations should treat this update as a high priority.
Zoom recommends that all users and IT administrators update affected systems to the latest available versions as soon as possible to reduce exposure to potential attacks.
Read More