CVE Tools

Zoom Patches Critical Windows Flaw That Could Enable Account Takeover

The Hacker NewsBy The Hacker News

PatchZoom Desktop ClientZoom VDI Client

Our summary

Zoom has issued security updates addressing a critical vulnerability affecting its Windows-based products, which could have allowed attackers to take over user accounts remotely. The flaw, identified as CVE-2026-53412 with a CVSS score of 9.8, impacts the Zoom Desktop Client, Zoom VDI Client, and Zoom Meeting SDK for Windows. According to Zoom’s advisory, an unauthenticated attacker could exploit this issue through network access without prior authentication. In addition to this critical flaw, three other high-severity vulnerabilities were also resolved in the latest releases.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store