Skip to content
October 6, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Vulnerability Report
  • CVE-2026-53412: CVSS 9.8 Zoom Vulnerability Allows Unauthenticated Account Takeover
  • Vulnerability Report

CVE-2026-53412: CVSS 9.8 Zoom Vulnerability Allows Unauthenticated Account Takeover

Do Son July 15, 2026 2 minutes read
0
Zoom vulnerability CVE-2026-53412 account takeover flaw in Zoom Workplace for Windows
Add Daily CyberSecurity as a preferred source on Google

TL;DR

Zoom has patched four flaws across its Windows products. The most severe Zoom vulnerability, CVE-2026-53412 (CVSS 9.8), allows an unauthenticated user to perform an account takeover over the network. Three other bugs enable local privilege escalation. Zoom has not reported in-the-wild exploitation or public proof-of-concept code for any of them.

Route critical Microsoft CVEs to one Slack channel, everything else to another.

Try Team free for 14 days →

Why It Matters

Zoom sits on millions of corporate desktops, so client flaws reach a wide audience. A network-reachable account takeover needs no credentials and no user interaction. Consequently, CVE-2026-53412 poses the sharpest risk in this batch. The three privilege escalation bugs matter too, since attackers chain them after gaining a foothold.

How the Attacks Work

CVE-2026-53412: Account Takeover (CVSS 9.8)

Improper input validation affects the Zoom Desktop Client, VDI Client, and Meeting SDK for Windows. The gap lets an unauthenticated attacker take over an account across the network.

Three Local Privilege Escalation Flaws

CVE-2026-53411 (CVSS 7.8) stems from improper input validation in the Workplace VDI Plugin. Meanwhile, CVE-2026-53409 (CVSS 7.8) involves improper privilege management in Zoom Rooms. Rounding out the set, CVE-2026-53410 (CVSS 7.0) is a time-of-check to time-of-use race condition during install and uninstall. Each requires an authenticated local user.

Affected Versions

The account takeover flaw hits Zoom Workplace for Windows before 7.0.0, the VDI Client before 7.0.10, 6.6.15, and 6.5.18 in their branches, and the Meeting SDK before 7.0.0. The race condition affects Workplace before 7.0.5, VDI Client and plugin before 6.5.17 and 6.6.14, Zoom Rooms before 7.0.5, and Remote Control for Zoom Contact Center before 7.0.0. Separately, the VDI Plugin flaw affects builds before 6.6.14, and the Zoom Rooms flaw affects versions before 7.1.0.

Patch and Mitigation Steps

Update every affected Zoom product to the fixed version listed above. Home users should grab the latest builds from Zoom’s download page. Administrators, meanwhile, should push updates through managed deployment and confirm VDI plugin and client versions match.

Related coverage

  • Critical wolfSSL Flaw Could Allow Attackers to Spoof Trusted Hosts
  • CVE-2026-18885 (CVSS 10): ServiceNow Code Injection and SQL Injection Flaws Patched
  • CVE-2026-69836 (CVSS 10): Entra ID Remote Code Execution Flaw
  • “New” Path of Attack: Fully Upgraded Fortinet Devices Hit by SSO Exploits
  • The Zero-Click Vulnerability: Akamai Uncovers Incomplete Patch for APT28 Exploit
  • Stirling PDF RCE CVE-2026-85714: Details and PoC Publicly Disclosed
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.

We respect your inbox. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Account Takeover privilege escalation windows Zoom

Leave a Reply Cancel reply

You must be logged in to post a comment.

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
  • CVE-2026-104286CVSS 9.8
    An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through...
    CISA KEV📅 Added to KEV: Oct 1, 2026
  • CVE-2026-76504CVSS 9.8
    A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 30, 2026📅 Updated: Sep 30, 2026
  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intelCISA KEV📅 Added to KEV: Sep 29, 2026📅 Updated: Sep 29, 2026
  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-51886CVSS 9.8
    langflow-ai langflow v1.9.3 is affected by: Code Injection. The impact is: execute arbitrary code (remote). The component is:...
    📅 Updated: Oct 6, 2026
  • CVE-2026-51881CVSS 9.8
    deeptutor 1.4.0 contains code injection in ExecTool.execute. Through the live tutorbot WebSocket interface, a remote caller can induce...
    📅 Updated: Oct 6, 2026
  • CVE-2026-51876CVSS 9.1
    DeepTutor 1.4.0 contains an authorization bypass vulnerability in the book confirmation flow. An unauthenticated or unauthorized caller can...
    📅 Updated: Oct 6, 2026
  • CVE-2026-105484CVSS 10.0
    A security vulnerability has been detected in TOTOLINK X6000R 9.4.0cu.652_B20230116. The impacted element is the function firmware_check of...
    📅 Updated: Oct 6, 2026
  • CVE-2026-105763CVSS 9.6
    Twenty is an open-source CRM (customer relationship management) platform. From 1.20.10 until 2.7.0, the /metadata GraphQL connectedAccounts query...
    📅 Updated: Oct 6, 2026
  • CVE-2025-12543CVSS 9.6
    A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and...
    📅 Updated: Oct 6, 2026
  • CVE-2026-90711CVSS 9.1
    ### Impact `proxy-addr` determines which network hops are trusted proxies so that `X-Forwarded-For` can be believed. When an...
    📅 Updated: Oct 5, 2026
  • CVE-2026-100721CVSS 10.0
    ## Summary At source revision `91034466bfb7f56b95fd48083ec6ca36d058f164` of vm2 3.11.8, an untrusted `NodeVM` guest can turn one allowlisted custom-resolved...
    📅 Updated: Oct 5, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.