CVE-2026-53412

Published Jul 16, 2026

Last updated 9 days ago

Overview

Description
Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an account takeover via network access.
Source
security@zoom.us
NVD status
Analyzed
Products
workplace_desktop, workplace_virtual_desktop_infrastructure

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

security@zoom.us
CWE-20

Social media

Hype score
Not currently trending
  1. 🚨 Patch Now | August 18, 2026 Today's vulnerabilities are as follows; - GitLab (CVE-2026-19478, CVSS 9.4) - Zoom for Windows (CVE-2026-53412, CVSS 9.8) - WordPress Forminator Forms (CVE-2026-15748, CVSS 9.8) https://t.co/fR71dyoG2H | #CyberSafeUG https://t.co/yYzCFkUhrZ

    @CERT_UG

    18 Aug 2026

    120 Impressions

    2 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. ⚠️ Vulnerabilidades en productos Zoom ❗ CVE-2026-53412 ❗ CVE-2026-53411 ❗ CVE-2026-53409 ➡️ Más info: https://t.co/MJIju4bNgi https://t.co/PoDBBfLacl

    @CERTpy

    24 Jul 2026

    156 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  3. Zoom CVE-2026-53412 (CVSS 9.8): unauth account takeover on Windows clients. Workplace before 7.0.0; VDI fixed at 7.0.10 / 6.6.15 / 6.5.18. Network improper input validation. Update Windows/VDI Zoom now. https://t.co/K1uI9MaV5i #CyberSecurity #CVE

    @snypet86

    19 Jul 2026

    58 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨*CVE* CVE-2026-53412 Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to condu… https://t.co/jb20PLfXlJ ----- Traducción: CVE-2026-53412 Val… https://t.co/utmtNg

    @infoflowcloud

    16 Jul 2026

    36 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. New critical flaws: Zoom (CVE-2026-53412) allows unauthenticated account takeover, risking real-time comms privacy. SonicWall zero-days (CVE-2026-15409/15410) enable RCE, jeopardizing network data integrity. Patch ASAP! #Cybersecurity #ZeroDay #News

    @YourAnon_irc

    16 Jul 2026

    60 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.