Zoom has warned that crucial vulnerabilities exist in its desktop shopper and software program growth package for Home windows that could possibly be exploited by unauthorized events to take over accounts.
The safety concern found internally was tracked as CVE-2026-53412 and had a severity rating of 9.8 out of 10.
On this week’s advisory, the messaging platform says the flaw impacts Zoom Office for Home windows earlier than model 7.0.0, Home windows VDI shoppers earlier than variations 7.0.10, 6.6.15, and 6.5.18, and Conferences SDK for Home windows earlier than model 7.0.0.
Zoom Office (beforehand referred to as Zoom) is a desktop collaboration software for video conferencing, group chat, VoIP cellphone calls, calendaring, e-mail, doc collaboration, whiteboarding, and AI-powered productiveness options.
Home windows desktop shoppers are extensively deployed and utilized by thousands and thousands of people and organizations all over the world.
The seller didn’t present technical particulars concerning the flaw in its safety bulletin, solely describing it as a difficulty with improper enter validation.
“Improper enter validation within the Zoom Desktop Consumer for Home windows, Zoom VDI Consumer for Home windows, and Zoom Conferences SDK for Home windows might enable an unauthenticated consumer to carry out account takeover through community entry,” the safety advisory states.
To cut back the danger attributable to CVE-2026-53412, the corporate recommends customers apply the most recent updates.
Zoom’s newest safety patch additionally addresses the next much less critical flaws:
- CVE-2026-53410: Excessive severity TOCTOU (Time to Test to Time of Use) race situation in Zoom Office for Home windows earlier than 7.0.5, Zoom Office VDI Consumer and VDI Plugin earlier than 6.5.17/6.6.14, Zoom Rooms for Home windows earlier than 7.0.5, and Zoom Contact Middle Distant earlier than 7.0.0 Impacts management. This flaw might enable an authenticated native consumer to escalate privileges throughout set up or uninstallation.
- CVE-2026-53409: Excessive severity improper privilege administration flaw affecting Zoom Rooms for Home windows earlier than model 7.1.0 permits authenticated customers with native entry to doubtlessly escalate their privileges.
- CVE-2026-53411: Excessive severity improper enter validation flaw affecting the Zoom Office VDI plugin for Home windows earlier than model 6.6.14 permits authenticated customers with native entry to doubtlessly escalate their privileges.
On the time of publication, there isn’t a proof that the vulnerability fastened by Zoom has been exploited in an assault.

Safety groups doc 54% of profitable assaults and concern a warning on solely 14%. The remainder strikes invisibly by means of the atmosphere.
Picus’ whitepaper reveals how one can check your SIEM and EDR guidelines in breach and assault simulations to make sure threats go undetected.
Get the white paper
