Zoom warns of critical account takeover vulnerability

Zoom has issued a critical security warning to millions of users worldwide, revealing that its desktop client and software development kit for Windows are vulnerable to account takeover attacks. The flaw, tracked as CVE-2026-53412, has been assigned a severity score of 9.8 out of 10, indicating it’s one of the most serious vulnerabilities Zoom has ever faced.

The issue affects users of Zoom Workplace for Windows before version 7.0.0, the Windows VDI Client before versions 7.0.10, 6.6.15, and 6.5.18, as well as the Meeting SDK for Windows before version 7.0.0. For context, Zoom Workplace is a popular desktop collaboration application used by millions of individuals and organizations worldwide. It offers video meetings, group chat, VoIP phone calls, calendar management, email, document collaboration, whiteboards, and AI-powered productivity features.

According to the security advisory issued by Zoom, the vulnerability stems from an “improper input validation” issue, which allows an unauthenticated user to conduct an account takeover via network access. While Zoom hasn’t provided technical details about the flaw, it’s essential for users to understand that this type of vulnerability can be exploited remotely without requiring any login credentials.

The good news is that Zoom has already released patches to address the critical vulnerability, and we recommend that all affected users apply the latest updates as soon as possible. In addition to CVE-2026-53412, the patches also fix three other less severe flaws: CVE-2026-53410, CVE-2026-53409, and CVE-2026-53411.

It’s worth noting that there are no indications of any attacks exploiting these vulnerabilities at this time. However, we must emphasize the importance of keeping software up-to-date to prevent potential security breaches. As a precautionary measure, users should also be aware of phishing attempts or other social engineering tactics that might try to trick them into revealing sensitive information.

In light of this incident, it’s essential for organizations and individuals alike to prioritize security updates and patches. Regularly applying the latest security fixes can help prevent account takeover attacks like this one and reduce the risk of successful breaches. As we always say at CyberNews.work: test every layer before attackers do. Stay vigilant, and stay secure!


Source: Bleeping Computer — 2026-07-15