Zoom has released security updates for a critical vulnerability, identified as CVE-2026-53412, affecting its Zoom Workplace and Zoom Workplace VDI clients for Windows. This flaw could enable an unauthenticated remote attacker to gain control of an affected Zoom account through network access. Zoom's Offensive Security team discovered the issue internally and disclosed it on July 14, 2026. The company has assigned the vulnerability a CVSS v3.1 score of 9.8 out of 10, categorizing it as critical.
The vulnerability is described as an improper input validation flaw within Zoom's Windows clients. While Zoom has not disclosed the specific technical details, the combination of remote accessibility, lack of authentication requirement, low complexity, and no user interaction makes CVE-2026-53412 particularly severe. Organizations with extensive Windows Zoom deployments are urged to identify vulnerable installations and deploy the fixed versions promptly.
Affected versions include Zoom Workplace for Windows before version 7.0.0, Zoom Workplace VDI Client for Windows 7.0 branch before version 7.0.10, Zoom Workplace VDI Client for Windows 6.6 branch before version 6.6.15, and Zoom Workplace VDI Client for Windows 6.5 branch before version 6.5.18. Initially, the Zoom Meeting SDK for Windows was also listed as affected, but a revision to security bulletin ZSB-26014 on July 15 removed it from the list. The current advisory indicates that only Windows products are affected, with macOS, Linux, Android, and iOS clients not listed as vulnerable to CVE-2026-53412.
Users are advised to update their Zoom Workplace application to version 7.0.0 or later as soon as possible. For Windows users who do not update by July 20, 2026, continued use of Zoom Workplace will require an upgrade. Users can check for updates by opening the Zoom Workplace desktop app, selecting their profile picture, and choosing "Check for Updates."
This recent vulnerability follows a history of security concerns for Zoom. In March 2021, an information disclosure vulnerability (CVE-2021-28133) in Zoom's screen sharing feature allowed other meeting participants to briefly view content from unshared application windows when they overlapped a shared window. This exposure, while brief, could potentially leak sensitive data. SySS researchers Michael Strametz and Matthias Deeg identified this flaw, which affected Zoom client versions through 5.5.4 on Windows and Linux. Zoom acknowledged this issue and was working on fixes at that time.
In 2018, Tenable Research discovered a vulnerability (CVE-2018-15715) that could allow a remote attacker to hijack screen controls, spoof chat messages, and remove attendees from meetings. That flaw affected Zoom version 4.1.33259.0925 for macOS and Windows, and version 2.4.129780.0915 for Ubuntu. Zoom quickly released updates to address this issue.
The company maintains a secure software development lifecycle, incorporating design reviews, code reviews, and static and dynamic analysis testing to identify and remediate vulnerabilities. Zoom also conducts security assessments of its third-party subprocessors annually. Despite these measures, new vulnerabilities continue to emerge, highlighting the ongoing challenge of securing widely used communication platforms.
Zoom regularly enforces minimum client versions to ensure users benefit from the latest security and functionality improvements. The company sets a platform minimum version every three months, providing advance notice to customers. Users on older versions may be at risk for bugs and vulnerabilities that have been resolved in more recent updates.
