Skip to content
September 15, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Vulnerability Report
  • CVE-2026-53412: CVSS 9.8 Zoom Vulnerability Allows Unauthenticated Account Takeover
  • Vulnerability Report

CVE-2026-53412: CVSS 9.8 Zoom Vulnerability Allows Unauthenticated Account Takeover

Do Son July 15, 2026 2 minutes read
0
Zoom vulnerability CVE-2026-53412 account takeover flaw in Zoom Workplace for Windows
Add Daily CyberSecurity as a preferred source on Google

TL;DR

Zoom has patched four flaws across its Windows products. The most severe Zoom vulnerability, CVE-2026-53412 (CVSS 9.8), allows an unauthenticated user to perform an account takeover over the network. Three other bugs enable local privilege escalation. Zoom has not reported in-the-wild exploitation or public proof-of-concept code for any of them.

Track every Microsoft CVE the moment it's exploited.

Get free email alerts →

Why It Matters

Zoom sits on millions of corporate desktops, so client flaws reach a wide audience. A network-reachable account takeover needs no credentials and no user interaction. Consequently, CVE-2026-53412 poses the sharpest risk in this batch. The three privilege escalation bugs matter too, since attackers chain them after gaining a foothold.

How the Attacks Work

CVE-2026-53412: Account Takeover (CVSS 9.8)

Improper input validation affects the Zoom Desktop Client, VDI Client, and Meeting SDK for Windows. The gap lets an unauthenticated attacker take over an account across the network.

Three Local Privilege Escalation Flaws

CVE-2026-53411 (CVSS 7.8) stems from improper input validation in the Workplace VDI Plugin. Meanwhile, CVE-2026-53409 (CVSS 7.8) involves improper privilege management in Zoom Rooms. Rounding out the set, CVE-2026-53410 (CVSS 7.0) is a time-of-check to time-of-use race condition during install and uninstall. Each requires an authenticated local user.

Affected Versions

The account takeover flaw hits Zoom Workplace for Windows before 7.0.0, the VDI Client before 7.0.10, 6.6.15, and 6.5.18 in their branches, and the Meeting SDK before 7.0.0. The race condition affects Workplace before 7.0.5, VDI Client and plugin before 6.5.17 and 6.6.14, Zoom Rooms before 7.0.5, and Remote Control for Zoom Contact Center before 7.0.0. Separately, the VDI Plugin flaw affects builds before 6.6.14, and the Zoom Rooms flaw affects versions before 7.1.0.

Patch and Mitigation Steps

Update every affected Zoom product to the fixed version listed above. Home users should grab the latest builds from Zoom’s download page. Administrators, meanwhile, should push updates through managed deployment and confirm VDI plugin and client versions match.

Related coverage

  • vLLM Flaw (CVE-2025-62164) Risks Remote Code Execution via Malicious Prompt Embeddings
  • High-severity flaw (CVE-2025-8069) in AWS Client VPN for Windows Allows Privilege Escalation
  • Critical Flaw (CVE-2025-8070) in ASUSTOR Backup & EZSync Allows Local SYSTEM Privilege Escalation
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Stay Ahead of the Threat

Join security professionals receiving zero-hour CVE alerts, PoC updates, and threat analysis directly to their inbox.

No spam. One actionable email per week. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Account Takeover privilege escalation windows Zoom

Leave a Reply Cancel reply

You must be logged in to post a comment.

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-87827CVSS 10.0
    Certain KGUARD DVR devices running vulnerable firmware expose a system command execution service on all network interfaces without...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-78006CVSS 9.8
    The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to,...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-39364
    Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-27540CVSS 9.0
    Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-76461CVSS 9.8
    A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an...
    CISA KEV📅 Added to KEV: Sep 14, 2026
  • CVE-2026-51990
    A critical remote code execution vulnerability in Sogou Input Method, one of the most widely used Chinese-language input...
    Admin intel📅 Updated: Sep 12, 2026
  • CVE-2026-85706CVSS 10.0
    GitLab has remediated an issue that, under certain conditions, an unauthenticated user could have read arbitrary files from...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-42016CVSS 8.1
    JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-63696CVSS 9.1
    Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of...
  • CVE-2026-63695CVSS 9.8
    Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation...
  • CVE-2026-39919CVSS 9.8
    Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG...
  • CVE-2026-91998CVSS 9.9
    Casdoor through 4.4.0 contains an authorization bypass vulnerability in the /api/mcp endpoint...
  • CVE-2026-91995CVSS 9.1
    pig before 4.1.0 contains an authentication bypass vulnerability in the /register/password endpoint...
  • CVE-2026-90711CVSS 9.1
    proxy-addr is a Node.js module that determines a request's client address behind...
  • CVE-2026-91003CVSS 9.1
    A flaw has been found in D-Link DI-8300 16.07. The affected element...
  • CVE-2026-91001CVSS 9.9
    A security flaw has been discovered in D-Link DI-8400 16.07. This affects...
  • CVE-2026-90847CVSS 9.1
    A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element...
  • CVE-2026-12944CVSS 9.6
    IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary...
Powered by CVE WATCHTOWER

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.