Junglewise Threat Intelligence

CVE-2026-53412: Zoom Workplace for Windows improper input validation account takeover

CVE-2026-53412 · Severity: critical · CVSS 9.8 · Published 2026-07-16

Technologies: Zoom Workplace VDI Client for Windows, Zoom Workplace, Zoom Workplace VDI Client. Vendors: Zoom.

Executive brief

A vulnerability in the Zoom application for Windows could allow an unauthorized person to take over a user's account over the network. Zoom is a widely used communication platform for video conferencing, chat, and collaboration. An exploit could lead to unauthorized access to sensitive meetings, private messages, and personal user data, potentially compromising corporate communications.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Zoom Desktop Client and VDI Client for Windows. The flaw allows a remote, unauthenticated attacker to perform an account takeover via network-based vectors without requiring any user interaction. While the specific protocol or input field is not detailed in the advisory, the CVSS vector indicates a low attack complexity and high impact on confidentiality, integrity, and availability. Users are advised to update to Zoom Workplace for Windows version 7.0.0 or later, and corresponding patched versions for the VDI client. Note that the Meeting SDK was initially listed but later removed from the affected products list by the vendor.

Affected products

  • Zoom Workplace for Windows before 7.0.0
  • Zoom Workplace VDI Client for Windows before 7.0.10, 6.6.15, and 6.5.18

Timeline

  • 2026-07-14: advisory: Initial publication by Zoom (ZSB-26014)
  • 2026-07-15: other: Advisory updated to remove Meeting SDK from affected products
  • 2026-07-16: disclosed: CVE published to NVD dataset

References

Related threats