// Service

Zoom

Video conferencing platform with healthcare and education tiers.

// Alerts

Recent threats

Zoom disclosed CVE-2026-53412, a vulnerability affecting Zoom Workplace for Windows and Zoom Workplace VDI Client for Windows. The flaw stems from improper input validation and allows unauthenticated attackers to remotely compromise Zoom user accounts over a network. Successful exploitation enables account takeover and unauthorized access to meetings, chat conversations, recordings, and shared files, with potential for data exfiltration and social engineering attacks. Nigeria's NITDA-CERRT issued an advisory recommending immediate updates and multi-factor authentication.

Zoom disclosed four vulnerabilities affecting Zoom Workplace, Zoom Rooms, Meeting SDK, Video SDK, and VDI products. CVE-2026-53413 and CVE-2026-53415 allow remote code execution via buffer overwrite and use-after-free in the annotator function; CVE-2026-53414 enables denial of service; CVE-2026-53416 permits information disclosure via path traversal in VDI Client. CVSS scores range from 6.5 to 8.3. Patches have been released across affected products.

// ZoomCRITICAL

A Security disclosed a critical Zoom vulnerability affecting screen sharing that allowed remote code execution on devices running Windows, macOS, Linux, iOS, and Android. The flaw enabled attackers to silently take over participant or host devices during calls with screen sharing enabled, requiring no user interaction or indication of attack. Zoom patched the vulnerability following coordinated disclosure.

// ZoomCRITICAL

Zoom patched a critical zero-click code execution vulnerability (CVE-2026-53413) in its annotation feature that allowed a meeting participant to execute arbitrary code on another participant's machine. The memory corruption flaw affected Zoom clients on all supported platforms and was discovered by A Security, which named the vulnerability Zoomsday. Patches have been rolled out.

// ZoomCRITICAL

Zoom disclosed CVE-2026-53412, a critical improper input validation vulnerability (CVSS 9.8) in its Windows desktop client, VDI client, and Meeting SDK that allows unauthenticated attackers to conduct account takeover via network access. Affected versions include Zoom Workplace for Windows before 7.0.0, VDI Client before versions 7.0.10/6.6.15/6.5.18, and Meeting SDK before 7.0.0. Zoom recommends immediate patching.

// ZoomMEDIUM

Zoom has released patches for three vulnerabilities affecting Zoom Rooms for Windows, the Zoom Workplace VDI Plugin for Windows, and Zoom Workplace for iOS. CVE-2026-30906 is an untrusted search path weakness in the Zoom Rooms Windows installer that allows an authenticated local user to escalate privileges, and CVE-2026-30905 is an external control of file name or path flaw in the Zoom Workplace VDI Plugin Windows Universal Installer that enables similar local privilege escalation; both are rated high severity and were reported by researcher sim0nsecurity. CVE-2026-30904 is a low-severity protection-mechanism failure in Zoom Workplace for iOS (CVSS 1.8) that requires physical access and high privileges to disclose sensitive information, reported by errorsec_. No active exploitation has been reported. Zoom has issued fixes via its official download portal, and administrators are advised to apply the latest updates promptly.