CVE-2026-53412 – Zoom Workplace for Windows

CVSS 9.8 CRITICAL Critical - Same Day Deployment

“A single validation mistake can become a direct path to losing control of an account.”

Zoom Communications has released a security update for Zoom Workplace for Windows to address CVE-2026-53412, an improper input validation vulnerability (CWE-20). The issue affects the Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows. An unauthenticated attacker could exploit the vulnerability over the network to perform an account takeover. The CVSS score is 9.8, which is Critical severity.

The update strengthens input validation to prevent unauthorized account takeover through network-based attacks. There is no verified evidence of public proof-of-concept code or real-world exploitation associated with this vulnerability.

Key Details

Affected Product
Zoom Workplace Desktop
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-20
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.