Advisory Date: 18 August 2026
Severity: Critical
CVSS v3.1: 9.8
CWE: CWE-20 — Improper Input Validation
Affected Platform: Microsoft Windows
CVE: CVE-2026-53412
Vendor Advisory: ZSB-26014
Executive Summary
A critical vulnerability, CVE-2026-53412, affects certain versions of Zoom Workplace and Zoom Workplace VDI Client for Windows. The vulnerability is caused by improper input validation and may allow an unauthenticated attacker with network access to take over a Zoom account.
The vulnerability carries a CVSS v3.1 score of 9.8 (Critical) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. This means exploitation is network-accessible, requires low attack complexity, requires no authentication or privileges, and requires no user interaction. Successful exploitation could have a high impact on confidentiality, integrity, and availability.
The National Vulnerability Database currently records the vulnerability as having total technical impact and being automatable, while NVD itself has not assigned a separate CVSS score
Organizations using Zoom on Windows should treat this as a priority patching issue.
Affected Products
According to Zoom’s current security bulletin, the following versions are affected:
| Product | Vulnerable Versions | Fixed Version |
|---|---|---|
| Zoom Workplace for Windows | Versions before 7.0.0 | 7.0.0 or later |
| Zoom Workplace VDI Client for Windows | Versions before 7.0.10 in the 7.0 branch | 7.0.10 or later |
| Zoom Workplace VDI Client for Windows | Versions before 6.6.15 in the 6.6 branch | 6.6.15 or later |
| Zoom Workplace VDI Client for Windows | Versions before 6.5.18 in the 6.5 branch | 6.5.18 or later |
Zoom subsequently revised its bulletin to remove the Zoom Meeting SDK for Windows from the affected-product list
Vulnerability Details
CVE-2026-53412 is classified as CWE-20, Improper Input Validation. In practical terms, the affected Windows software does not adequately validate certain input before processing it.
The published information does not disclose the precise vulnerable component, protocol, request format, or exploitation mechanism. Zoom’s advisory states only that improper input validation may permit an unauthenticated user to conduct an account takeover through network access
The CVSS vector is particularly concerning:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
This translates to:
- AV:N — Network: exploitation can occur remotely over a network.
- AC:L — Low: exploitation does not require unusual or difficult conditions.
- PR:N — None: the attacker does not need an existing account or privileges.
- UI:N — None: the victim does not need to click, approve, or otherwise interact.
- C:H — High: confidentiality could be significantly compromised.
- I:H — High: integrity could be significantly compromised.
- A:H — High: availability could be significantly affected.
Potential Business Impact
Successful exploitation could result in unauthorized takeover of a user’s Zoom account. Depending on the privileges and resources associated with the compromised account, this could expose an organization to:
- Unauthorized access to Zoom resources and account information.
- Impersonation of legitimate users.
- Unauthorized participation in or management of meetings.
- Exposure of sensitive meeting or collaboration information.
- Abuse of organizational Zoom functionality.
- Further attacks using the compromised account as a trusted identity.
- Reputational, operational, privacy, and regulatory consequences.
The exact post-compromise capabilities will depend on the privileges assigned to the affected Zoom account and the organization’s Zoom configuration.
Exploitation Status
At the time of this advisory, there is no indication in the record that CVE-2026-53412 is listed as a Known Exploited Vulnerability. However, the vulnerability’s attack characteristics make it inappropriate to wait for confirmed exploitation before patching.
SSVC data associated with the CVE records exploitation as “none,” automatable as “yes,” and technical impact as “total.”Security teams should also note that the absence of publicly confirmed exploitation does not mean that vulnerable systems are safe to leave unpatched.
Recommended Remediation
1. Patch affected Windows endpoints immediately
Organizations should upgrade Zoom Workplace for Windows to version 7.0.0 or later.
For VDI environments, administrators should upgrade to an appropriate fixed branch:
- 7.0.10 or later
- 6.6.15 or later
- 6.5.18 or later
Zoom directs customers to its download channel for the latest security updates.
2. Identify vulnerable installations
Use endpoint-management, software-inventory, or EDR tooling to identify Windows systems running:
- Zoom Workplace < 7.0.0
- Zoom Workplace VDI Client < 7.0.10 on the 7.0 branch
- Zoom Workplace VDI Client < 6.6.15 on the 6.6 branch
- Zoom Workplace VDI Client < 6.5.18 on the 6.5 branch
Prioritize internet-connected endpoints, privileged users, executives, administrators, and systems used to access sensitive corporate meetings or information.
3. Review Zoom account activity
Where feasible, review authentication and account activity for anomalous behavior, particularly for users who were running vulnerable versions.
Look for:
- Unexpected account logins.
- Unusual geographic locations or IP addresses.
- Unexpected session activity.
- Changes to account security settings.
- Unexpected meeting or administrative activity.
- Suspicious activity involving high-privilege Zoom accounts.
Because the vulnerability is potentially capable of account takeover, organizations should not limit investigation to endpoint compromise alone.
4. Consider credential/session remediation where compromise is suspected
If an affected endpoint or account shows evidence of suspicious activity, follow the organization’s incident-response procedures. Depending on the findings, this may include terminating active sessions, resetting credentials, reviewing MFA configuration, and investigating activity performed through the account.


Leave a Reply