Zoom Patches Critical Windows Client Flaw (CVE-2026-53412, CVSS 9.8) Enabling Unauthenticated Account Takeover
Zoom Patches Critical Windows Client Flaw (CVE-2026-53412 (TL-2026-1405) is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-07-16 and last reviewed 2026-07-18. It has no confirmed attribution, affects Zoom Zoom Desktop Client for Windows (Zoom Workplace for Windows), references 4 CVEs (CVE-2026-53412, CVE-2026-53411, CVE-2026-53410), maps to 18 MITRE ATT&CK techniques (T1068, T1078, T1082), and is covered by 9 detection rules and 16 indicators of compromise.
Key facts for TL-2026-1405
- Threat ID
- TL-2026-1405
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-07-16
- Last reviewed
- 2026-07-18
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, government administration, finance, health, education, professional-services, telecoms, retail
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 16
- Updates
- 2026-07-18 · revalidated 1× · latest source
Zoom disclosed CVE-2026-53412, a critical improper-input-validation flaw in the Zoom Desktop Client, VDI Client, and Meeting SDK for Windows that lets an unauthenticated, network-adjacent attacker take over a victim's Zoom account with no user interaction. Zoom bundled the disclosure with three high-severity local privilege-escalation flaws (CVE-2026-53411, CVE-2026-53410, CVE-2026-53409) affecting the VDI Plugin, cross-client installer/uninstaller TOCTOU handling, and Zoom Rooms for Windows. No in-the-wild exploitation or public PoC has been reported as of publication (2026-07-16); the vulnerabilities are not (yet) listed in the CISA KEV catalog.
How Zoom Patches Critical Windows Client Flaw (CVE-2026-53412 works
On 2026-07-14, Zoom published four coordinated security bulletins (ZSB-26011 through ZSB-26014) disclosing a set of Windows-client vulnerabilities patched in the same release train. The headline issue, CVE-2026-53412 (CVSS 3.1: 9.8, vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), is an improper-input-validation weakness (CWE-20) in the Zoom Desktop Client for Windows, the Zoom VDI Client for Windows, and the Zoom Meeting SDK for Windows. Because the attack vector is network (AV:N), requires no privileges (PR:N) and no user interaction (UI:N), an unauthenticated attacker who can reach a vulnerable client over the network can trigger the flaw to take over the victim's Zoom account -- the most severe class of remote compromise, comparable to unauthenticated RCE-adjacent account-takeover bugs in other widely deployed meeting/collaboration clients. Zoom credits its internal Offensive Security team with discovery, which is consistent with the absence of a public write-up, PoC, or third-party researcher credit and with the lack of confirmed exploitation.
Zoom bundled three companion high-severity, authenticated-local-only vulnerabilities into the same disclosure window, all of which require the attacker to already hold local, authenticated access to the Windows host -- a materially different (and lower-severity) trust boundary than CVE-2026-53412's unauthenticated network vector, but which combine with it to give an attacker a full initial-access-to-privilege-escalation chain if a target machine is compromised in stages:
- CVE-2026-53411 (CVSS 7.8, CWE-20 Improper Input Validation) -- affects the Zoom Workplace VDI Plugin for Windows before 6.6.14 (Zoom's own advisory language) / reported elsewhere as before 6.6.14 and 6.5.17 branches; allows an authenticated local user to escalate privileges. - CVE-2026-53410 (CVSS 7.0, CWE-367 Time-of-Check to Time-of-Use (TOCTOU) Race Condition) -- affects the install/uninstall routines shared across Zoom Workplace for Windows, the Windows VDI Client/Plugin, Zoom Rooms for Windows, and Remote Control for Zoom Contact Center; an authenticated local user can win a race during (un)installation to escalate privileges, a classic Windows installer-hijacking pattern (planting or swapping a file/service binary between a permission check and its use). - CVE-2026-53409 (CVSS 7.8, CWE-269 Improper Privilege Management) -- affects Zoom Rooms for Windows before 7.1.0; an authenticated local user can escalate privileges due to over-broad privilege assignment in the Rooms client/service.
Fixed versions per Zoom's bulletins and corroborating reporting: Zoom Workplace for Windows 7.0.0+ (account-takeover fix) / 7.0.5+ (TOCTOU fix); Windows VDI Client 6.5.18 / 6.6.15 / 7.0.10+ (branch-dependent); Zoom Rooms for Windows 7.1.0+ (privilege-management fix) / 7.0.5+ (TOCTOU fix); Zoom Workplace VDI Plugin 6.6.14+; Remote Control for Zoom Contact Center 7.0.0+. Organizations running any of these Windows clients should prioritize CVE-2026-53412 remediation given its unauthenticated, no-interaction, network-reachable profile, then apply the companion patches to close the local-privesc chain that could otherwise follow an initial foothold.
Given Zoom's massive installed base across enterprise, government, healthcare, and education sectors, and the fact that Zoom clients are frequently exposed to untrusted network segments (VDI pools, shared kiosks, BYOD-adjacent meeting rooms), this disclosure warrants tracking even absent confirmed exploitation: unauthenticated account-takeover primitives in ubiquitous collaboration software have historically drawn rapid reverse-engineering and exploit-development interest once patches ship (patch-diffing risk), and Zoom account compromise directly enables business-email-compromise-style social engineering, meeting hijacking, and downstream credential/data exposure.
MITRE ATT&CK techniques used in TL-2026-1405
Privilege Escalation
T1068 Exploitation for Privilege Escalation; T1548 Abuse Elevation Control Mechanism
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application
Discovery
T1082 System Information Discovery; T1518 Software Discovery
Execution
T1203 Exploitation for Client Execution
Defense Evasion
T1211 Exploitation for Stealth
Credential Access
T1212 Exploitation for Credential Access; T1528 Steal Application Access Token
Collection
T1213 Data from Information Repositories
Impact
T1499 Endpoint Denial of Service; T1531 Account Access Removal
Persistence
T1543 Create or Modify System Process
privilege-escalation
T1548 Abuse Elevation Control Mechanism
stealth
Resource Development
Reconnaissance
T1590 Gather Victim Network Information; T1595 Active Scanning
Affected products and versions in Zoom Patches Critical Windows Client Flaw (CVE-2026-53412
- Zoom — Zoom Desktop Client for Windows (Zoom Workplace for Windows)
Vulnerable versions: before 7.0.0; before 7.0.5
Fixed in: 7.0.0 (CVE-2026-53412); 7.0.5 (CVE-2026-53410) - Zoom — Zoom VDI Client for Windows
Vulnerable versions: before 6.5.18; before 6.6.15; before 7.0.10
Fixed in: 6.5.18; 6.6.15; 7.0.10 - Zoom — Zoom Workplace VDI Plugin for Windows
Vulnerable versions: before 6.6.14
Fixed in: 6.6.14 - Zoom — Zoom Meeting SDK for Windows
Vulnerable versions: before 7.0.0
Fixed in: 7.0.0 - Zoom — Zoom Rooms for Windows
Vulnerable versions: before 7.1.0; before 7.0.5
Fixed in: 7.1.0 (CVE-2026-53409); 7.0.5 (CVE-2026-53410) - Zoom — Remote Control for Zoom Contact Center
Vulnerable versions: before 7.0.0
Fixed in: 7.0.0
Remediation for Zoom Patches Critical Windows Client Flaw (CVE-2026-53412
Patches
- Zoom Workplace for Windows 7.0.0+ / 7.0.5+
- Zoom Meeting SDK for Windows 7.0.0+
- Zoom Workplace VDI Client for Windows 6.5.18 / 6.6.15 / 7.0.10
- Zoom Workplace VDI Plugin for Windows 6.6.14+
- Zoom Rooms for Windows 7.1.0+ / 7.0.5+
- Remote Control for Zoom Contact Center 7.0.0+
Immediate actions
- Upgrade Zoom Workplace for Windows to 7.0.0 or later (CVE-2026-53412 fix) and to 7.0.5 or later (CVE-2026-53410 fix)
- Upgrade Zoom Meeting SDK for Windows to 7.0.0 or later
- Upgrade Zoom VDI Client for Windows to 6.5.18, 6.6.15, or 7.0.10 (branch-dependent) and Zoom Workplace VDI Plugin to 6.6.14 or later
- Upgrade Zoom Rooms for Windows to 7.1.0 or later (CVE-2026-53409 fix) and to 7.0.5 or later (CVE-2026-53410 fix)
- Upgrade Remote Control for Zoom Contact Center to 7.0.0 or later
- Prioritize CVE-2026-53412 remediation on any Windows host running the affected Zoom clients that is reachable from untrusted or semi-trusted network segments
Workarounds
- If immediate patching is not possible, restrict network reachability to vulnerable Zoom Windows clients (firewall/network segmentation) as a stopgap for CVE-2026-53412
- Restrict local login/authenticated access to hosts running affected VDI/Rooms components to trusted administrators only, pending patching of the local-privesc CVEs
Longer-term hardening
- Enforce automatic update policies for Zoom Windows clients via enterprise deployment tooling (SCCM/Intune/Zoom's MSI admin push) rather than relying on end-user self-update
- Segment VDI pools and shared/kiosk Windows hosts running Zoom clients from untrusted network zones
- Restrict local administrative rights on endpoints running Zoom Rooms / VDI clients to reduce the blast radius of local privilege-escalation chains
- Maintain an inventory of Zoom client versions across the fleet to detect unpatched endpoints
CVEs associated with Zoom Patches Critical Windows Client Flaw (CVE-2026-53412
CVE-2026-53412, CVE-2026-53411, CVE-2026-53410, CVE-2026-53409
Weaknesses (CWE) in Zoom Patches Critical Windows Client Flaw (CVE-2026-53412
CWE-20, CWE-367, CWE-269
Timeline of Zoom Patches Critical Windows Client Flaw (CVE-2026-53412
- Fixed builds ship: Zoom Workplace for Windows 7.0.0/7.0.5, VDI Client 6.5.18/6.6.15/7.0.10, VDI Plugin 6.6.14, Zoom Rooms for Windows 7.0.5/7.1.0, and Remote Control for Zoom Contact Center 7.0.0.
- Zoom publishes four coordinated security bulletins (ZSB-26011, ZSB-26012, ZSB-26013, ZSB-26014) disclosing CVE-2026-53409, CVE-2026-53410, CVE-2026-53411, and CVE-2026-53412, with credit to Zoom's internal Offensive Security team.
- Security media (BleepingComputer, BetaNews, TechRepublic, securityonline.info) publish coverage summarizing the four CVEs and urging immediate patching.
- CVSS v3.1 base score of 9.8 (vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) for CVE-2026-53412 appears in third-party CVE trackers (e.g. Tenable).
- CVE-2026-53412 is published in the NVD (nvd.nist.gov/vuln/detail/CVE-2026-53412), corroborating the CVSS v3.1 base score of 9.8 and additionally recording a CVSS v2 score of 10.0.
- Zoom issues revision 1.1 of security bulletin ZSB-26014 (CVE-2026-53412), removing Zoom Meeting SDK for Windows from the affected-products list present in the original 1.0 publication -- narrowing the confirmed account-takeover exposure to Zoom Workplace for Windows and the Zoom Workplace VDI Client for Windows.
- Threadlinqs Intelligence threat record TL-2026-1405 compiled from vendor bulletins, CVE trackers, and news coverage.
- CISA Known Exploited Vulnerabilities catalog checked; none of the four CVEs (CVE-2026-53409/53410/53411/53412) are listed, consistent with vendor statements of no observed in-the-wild exploitation.
- The Hacker News publishes coverage of the disclosure, which serves as the initial hunt source for this threat record.
- NVD record for CVE-2026-53412 last modified, still in 'Awaiting Analysis' status with no change to CVSS scoring or affected-product data relative to the July 16 publication.
Update history for TL-2026-1405
- 2026-07-18 — CVE-2026-53412: Critical Unauthenticated Account Takeover in Zoom Windows Clients (CVSS 9.8): What changed No change to severity (CRITICAL), CVSS (9.8), exploitability (THEORETICAL), or status (ACTIVE) — both reports agree these are unchanged. New indicators (1) 1 new entity IOC: external researcher sim0nsecurity, credited with the
Sources cited for Zoom Patches Critical Windows Client Flaw (CVE-2026-53412
- Zoom Patches Critical Windows Flaw That Could Lead to Account Takeover
- Zoom warns of critical account takeover vulnerability
- CVE-2026-53412: CVSS 9.8 Zoom Vulnerability Allows Unauthenticated Account Takeover
- CVE-2026-53412
- Zoom Security Bulletin ZSB-26014 (CVE-2026-53412)
- Zoom Security Bulletins index
- Zoom issues a warning to Windows users about critical security flaw
- Windows Users at Risk as Critical Zoom Vulnerability Exploited
- Zoom: Zoom warns of critical account takeover vulnerability (Rankiteo)
- CISA Known Exploited Vulnerabilities Catalog (checked for CVE-2026-53412; not listed as of 2026-07-16)
Threats related to Zoom Patches Critical Windows Client Flaw (CVE-2026-53412
- Zoom Windows Apps Critical Unauthenticated Account Takeover (CVE-2026-53412) Plus Three Chained Local Privilege Escalation Flaws
- CVE-2026-53412: Unauthenticated Remote Account Takeover in Zoom Desktop Client, VDI Client, and Meeting SDK for Windows
- Microsoft July 2026 Patch Tuesday: Record 622 CVEs Include Two Actively Exploited Zero-Days in AD FS (CVE-2026-56155) and SharePoint Server (CVE-2026-56164)
- GNU Guix 'guix substitute' and 'guix pull' Vulnerabilities Enable Arbitrary File Write, Metadata Spoofing, Local Secret Disclosure, and Path Traversal (CVE Pending)
- DirtyClone Linux Kernel Local Privilege Escalation via __pskb_copy_fclone() (CVE-2026-43503)
Detection coverage for TL-2026-1405
As of 2026-07-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1405 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.