Zoom Issues Critical Warning for Account Takeover Vulnerability Affecting Millions of Users Worldwide
A critical vulnerability has been discovered in Zoom’s desktop client and software development kit for Windows, which could be exploited by an unauthenticated party to hijack user accounts. The security issue, tracked as CVE-2026-53412, affects millions of users who rely on the popular video conferencing platform for daily communication.
The flaw is particularly concerning because it allows an attacker to conduct an account takeover via network access without needing any authentication credentials. Zoom has rated the severity of this vulnerability a 9.8 out of 10, indicating that it poses a significant risk to user security. The company’s advisory explains that the issue stems from an “improper input validation” problem, but deliberately refrains from providing technical details.
The affected software components include Zoom Workplace for Windows before version 7.0.0, the Windows VDI Client before versions 7.0.10, 6.6.15, and 6.5.18, and the Meeting SDK for Windows before version 7.0.0. These vulnerabilities are not just limited to individual users; they also affect organizations that use Zoom Workplace, a comprehensive collaboration application with features like video meetings, group chat, VoIP phone calls, and document sharing.
Zoom recommends that all affected users apply the latest updates to mitigate the risks associated with this vulnerability. The company’s security patches address four flaws in total, including three high-severity issues (CVE-2026-53410, CVE-2026-53409, and CVE-2026-53411) that could allow attackers to escalate privileges or conduct unauthorized actions.
It is worth noting that at the time of disclosure, there were no indications that these vulnerabilities are being exploited in attacks. However, given their severity, it’s essential for users to act promptly to update their software and prevent potential security breaches.
For those who rely on Zoom for daily communication, this alert serves as a reminder to stay vigilant and ensure that all software is up-to-date. Regularly patching your systems and keeping your software current can go a long way in preventing unauthorized access to sensitive information.
Source: Bleeping Computer — 2026-07-15