Advisory Date: 18 August 2026
Severity: Critical
CVSS v3.1: 9.8
CWE: CWE-20 — Improper Input Validation
Affected Platform: Microsoft Windows
CVE: CVE-2026-53412
Vendor Advisory: ZSB-26014

Executive Summary

A critical vulnerability, CVE-2026-53412, affects certain versions of Zoom Workplace and Zoom Workplace VDI Client for Windows. The vulnerability is caused by improper input validation and may allow an unauthenticated attacker with network access to take over a Zoom account.

The vulnerability carries a CVSS v3.1 score of 9.8 (Critical) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. This means exploitation is network-accessible, requires low attack complexity, requires no authentication or privileges, and requires no user interaction. Successful exploitation could have a high impact on confidentiality, integrity, and availability.

The National Vulnerability Database currently records the vulnerability as having total technical impact and being automatable, while NVD itself has not assigned a separate CVSS score

Organizations using Zoom on Windows should treat this as a priority patching issue.

Affected Products

According to Zoom’s current security bulletin, the following versions are affected:

Product Vulnerable Versions Fixed Version
Zoom Workplace for Windows Versions before 7.0.0 7.0.0 or later
Zoom Workplace VDI Client for Windows Versions before 7.0.10 in the 7.0 branch 7.0.10 or later
Zoom Workplace VDI Client for Windows Versions before 6.6.15 in the 6.6 branch 6.6.15 or later
Zoom Workplace VDI Client for Windows Versions before 6.5.18 in the 6.5 branch 6.5.18 or later

Zoom subsequently revised its bulletin to remove the Zoom Meeting SDK for Windows from the affected-product list

Vulnerability Details

CVE-2026-53412 is classified as CWE-20, Improper Input Validation. In practical terms, the affected Windows software does not adequately validate certain input before processing it.

The published information does not disclose the precise vulnerable component, protocol, request format, or exploitation mechanism. Zoom’s advisory states only that improper input validation may permit an unauthenticated user to conduct an account takeover through network access

The CVSS vector is particularly concerning:

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

This translates to:

  • AV:N — Network: exploitation can occur remotely over a network.
  • AC:L — Low: exploitation does not require unusual or difficult conditions.
  • PR:N — None: the attacker does not need an existing account or privileges.
  • UI:N — None: the victim does not need to click, approve, or otherwise interact.
  • C:H — High: confidentiality could be significantly compromised.
  • I:H — High: integrity could be significantly compromised.
  • A:H — High: availability could be significantly affected.

Potential Business Impact

Successful exploitation could result in unauthorized takeover of a user’s Zoom account. Depending on the privileges and resources associated with the compromised account, this could expose an organization to:

  • Unauthorized access to Zoom resources and account information.
  • Impersonation of legitimate users.
  • Unauthorized participation in or management of meetings.
  • Exposure of sensitive meeting or collaboration information.
  • Abuse of organizational Zoom functionality.
  • Further attacks using the compromised account as a trusted identity.
  • Reputational, operational, privacy, and regulatory consequences.

The exact post-compromise capabilities will depend on the privileges assigned to the affected Zoom account and the organization’s Zoom configuration.

Exploitation Status

At the time of this advisory, there is no indication in the  record that CVE-2026-53412 is listed as a Known Exploited Vulnerability. However, the vulnerability’s attack characteristics make it inappropriate to wait for confirmed exploitation before patching.

SSVC data associated with the CVE records exploitation as “none,” automatable as “yes,” and technical impact as “total.”Security teams should also note that the absence of publicly confirmed exploitation does not mean that vulnerable systems are safe to leave unpatched.

Recommended Remediation

1. Patch affected Windows endpoints immediately

Organizations should upgrade Zoom Workplace for Windows to version 7.0.0 or later.

For VDI environments, administrators should upgrade to an appropriate fixed branch:

  • 7.0.10 or later
  • 6.6.15 or later
  • 6.5.18 or later

Zoom directs customers to its download channel for the latest security updates. 

2. Identify vulnerable installations

Use endpoint-management, software-inventory, or EDR tooling to identify Windows systems running:

  • Zoom Workplace < 7.0.0
  • Zoom Workplace VDI Client < 7.0.10 on the 7.0 branch
  • Zoom Workplace VDI Client < 6.6.15 on the 6.6 branch
  • Zoom Workplace VDI Client < 6.5.18 on the 6.5 branch

Prioritize internet-connected endpoints, privileged users, executives, administrators, and systems used to access sensitive corporate meetings or information.

3. Review Zoom account activity

Where feasible, review authentication and account activity for anomalous behavior, particularly for users who were running vulnerable versions.

Look for:

  • Unexpected account logins.
  • Unusual geographic locations or IP addresses.
  • Unexpected session activity.
  • Changes to account security settings.
  • Unexpected meeting or administrative activity.
  • Suspicious activity involving high-privilege Zoom accounts.

Because the vulnerability is potentially capable of account takeover, organizations should not limit investigation to endpoint compromise alone.

4. Consider credential/session remediation where compromise is suspected

If an affected endpoint or account shows evidence of suspicious activity, follow the organization’s incident-response procedures. Depending on the findings, this may include terminating active sessions, resetting credentials, reviewing MFA configuration, and investigating activity performed through the account.


Leave a Reply

Your email address will not be published. Required fields are marked *