ZeroHour
Security Affairspublished ()ingested @securityaffairs

Zoom Fixes CVE-2026

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-22844
A Command Injection vulnerability in Zoom Node Multimedia Routers (MMRs) before version 5.2.1716.0 may allow a meeting participant to conduct remote code execut

A Command Injection vulnerability in Zoom Node Multimedia Routers (MMRs) before version 5.2.1716.0 may allow a meeting participant to conduct remote code execution of the MMR via network access.

NVD description · AI analysis pending
9.913%
CVE-2026-53409
Improper Privilege Management in Zoom Rooms for Windows before version 7.1.0 may allow an authenticated user to conduct an escalation of privilege via local acc

Improper Privilege Management in Zoom Rooms for Windows before version 7.1.0 may allow an authenticated user to conduct an escalation of privilege via local access.

NVD description · AI analysis pending
7.8<1%
  • zoom rooms
CVE-2026-53410
A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authent

A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to escalate privileges.

NVD description · AI analysis pending
7.0<1%
  • zoom remote control for zoom contact center
  • zoom rooms
  • zoom workplace desktop
  • +1 more
CVE-2026-53411
A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authent

A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to escalate privileges.

NVD description · AI analysis pending
7.0<1%
  • zoom workplace virtual desktop infrastructure
CVE-2026-53412
Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to

Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an account takeover via network access.

NVD description · AI analysis pending
9.8<1%
  • zoom workplace desktop
  • zoom workplace virtual desktop infrastructure
Full article287 words · extracted from securityaffairs.com · click to collapse

Zoom warns of a critical Windows flaw, tracked as CVE-2026-53412, that could let attackers take over accounts without authentication.

Zoom has fixed a critical Windows vulnerability, tracked as CVE-2026-53412 (CVSS score of 9.8) that could allow unauthenticated attackers to hijack user accounts. The flaw affects older versions of Workplace, the Windows VDI Client, and the Meeting SDK for Windows.

“Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an account takeover via network access.” reads the advisory.

The company Offensive Security team discovered the vulnerability. The company did not provide technical details about the vulnerability.

The company also addressed the following vulnerabilities:

  • CVE-2026-53410 (CVSS score of 8.8) – A race condition in Zoom Workplace, VDI Client/Plugin, Rooms, and Remote Control for Zoom Contact Center on Windows could let an authenticated local user gain higher privileges during installation or uninstallation.
  • CVE-2026-53409 (CVSS score of 8.8) – An improper privilege management flaw in Rooms for Windows could let an authenticated local user escalate privileges.
  • CVE-2026-53411 (CVSS score of 8.8) – An input validation flaw in the Workplace VDI Plugin for Windows could let an authenticated local user gain elevated privileges.

Users should update to the latest versions as soon as possible.

None of the above issues is currently under active exploitation in the wild.

In January, the Cloud-based video conferencing and online collaboration platform released security updates to address multiple vulnerabilities, including command injection, tracked as CVE-2026-22844 (CVSS score of 9.9), in Node Multimedia Routers (MMRs) that could result in remote code execution.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Zoom)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/195454/security/zoom-fixes-cve-2026-53412-a-critical-account-takeover-bug.html