CVE-2026-53412 – Zoom Workplace for Windows
“A single validation mistake can become a direct path to losing control of an account.”
Zoom Communications has released a security update for Zoom Workplace for Windows to address CVE-2026-53412, an improper input validation vulnerability (CWE-20). The issue affects the Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows. An unauthenticated attacker could exploit the vulnerability over the network to perform an account takeover. The CVSS score is 9.8, which is Critical severity.
The update strengthens input validation to prevent unauthorized account takeover through network-based attacks. There is no verified evidence of public proof-of-concept code or real-world exploitation associated with this vulnerability.
Key Details
- Affected Product
- Zoom Workplace Desktop
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-20