Zoom Patches Critical Windows Flaw Enabling Account Takeover
ID: a43dbd35-f387-5d9f-8870-83d924254c61
STIX ID: report--a43dbd35-f387-5d9f-8870-83d924254c61
Feed Name: The Cyber Express
Zoom released security updates addressing CVE-2026-53412, a critical Improper Input Validation vulnerability (CVSS 9.8) in Zoom Desktop Client and Windows VDI clients that could allow an unauthenticated remote account takeover. The bulletin also patches three additional high-severity Windows vulnerabilities (privilege escalation and TOCTOU issues) affecting various Zoom for Windows branches; Zoom urges immediate updates and reports no evidence of active exploitation at publication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
