logo

Zoom warns of critical account takeover vulnerability

ID: 59304615-4fb9-54a2-aeb5-26d6c7aacfac

STIX ID: report--59304615-4fb9-54a2-aeb5-26d6c7aacfac

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-07-15

Date Updated: 2026-07-15

Author: Bill Toulas

...
...

Zoom disclosed a critical improper input validation vulnerability (CVE-2026-53412, CVSS 9.8) affecting Zoom Workplace for Windows, Windows VDI clients, and the Meeting SDK that could permit an unauthenticated attacker to take over accounts via network access; vendor patches are available and users are advised to update. The advisory also fixes several high-severity local privilege escalation and input validation flaws, and Zoom reported no evidence of in-the-wild exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.