Threat Intelligence / CVE / CVE-2026-53412
CVE-2026-53412
As of 2026-07-16, CVE-2026-53412 is a CVSS 9.8 (CRITICAL-severity) vulnerability. Threadlinqs Intelligence tracks 3 threats exploiting it.
Last updated: 2026-07-16
Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an account takeover via network access.
CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
CWE-20
Threats tracking this CVE
- CVE-2026-53412: Unauthenticated Remote Account Takeover in Zoom Desktop Client, VDI Client, and Meeting SDK for Windows — CRITICAL
- Zoom Patches Critical Windows Client Flaw (CVE-2026-53412, CVSS 9.8) Enabling Unauthenticated Account Takeover — CRITICAL
- Zoom Windows Apps Critical Unauthenticated Account Takeover (CVE-2026-53412) Plus Three Chained Local Privilege Escalation Flaws — CRITICAL
References
Full detection coverage & IOCs for threats exploiting CVE-2026-53412 are available via the Threadlinqs MCP server (Purple tier). View plans →
← all vulnerabilities · Markdown version · Threadlinqs Intelligence
Enriched from CVE.org, NVD (this product uses the NVD API but is not endorsed or certified by the NVD), FIRST EPSS, CISA KEV, and GitHub Security Advisories.