Zoom Patches Critical Windows Client Flaw (CVE-2026-53412, CVSS 9.8) Enabling Unauthenticated Account Takeover

Zoom Patches Critical Windows Client Flaw (CVE-2026-53412 (TL-2026-1405) is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-07-16 and last reviewed 2026-07-18. It has no confirmed attribution, affects Zoom Zoom Desktop Client for Windows (Zoom Workplace for Windows), references 4 CVEs (CVE-2026-53412, CVE-2026-53411, CVE-2026-53410), maps to 18 MITRE ATT&CK techniques (T1068, T1078, T1082), and is covered by 9 detection rules and 16 indicators of compromise.

Key facts for TL-2026-1405

Threat ID
TL-2026-1405
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-07-16
Last reviewed
2026-07-18
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, government administration, finance, health, education, professional-services, telecoms, retail
Target regions
Global
Detection rules
9
Indicators of compromise
16
Updates
2026-07-18 · revalidated 1× · latest source

Zoom disclosed CVE-2026-53412, a critical improper-input-validation flaw in the Zoom Desktop Client, VDI Client, and Meeting SDK for Windows that lets an unauthenticated, network-adjacent attacker take over a victim's Zoom account with no user interaction. Zoom bundled the disclosure with three high-severity local privilege-escalation flaws (CVE-2026-53411, CVE-2026-53410, CVE-2026-53409) affecting the VDI Plugin, cross-client installer/uninstaller TOCTOU handling, and Zoom Rooms for Windows. No in-the-wild exploitation or public PoC has been reported as of publication (2026-07-16); the vulnerabilities are not (yet) listed in the CISA KEV catalog.

How Zoom Patches Critical Windows Client Flaw (CVE-2026-53412 works

On 2026-07-14, Zoom published four coordinated security bulletins (ZSB-26011 through ZSB-26014) disclosing a set of Windows-client vulnerabilities patched in the same release train. The headline issue, CVE-2026-53412 (CVSS 3.1: 9.8, vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), is an improper-input-validation weakness (CWE-20) in the Zoom Desktop Client for Windows, the Zoom VDI Client for Windows, and the Zoom Meeting SDK for Windows. Because the attack vector is network (AV:N), requires no privileges (PR:N) and no user interaction (UI:N), an unauthenticated attacker who can reach a vulnerable client over the network can trigger the flaw to take over the victim's Zoom account -- the most severe class of remote compromise, comparable to unauthenticated RCE-adjacent account-takeover bugs in other widely deployed meeting/collaboration clients. Zoom credits its internal Offensive Security team with discovery, which is consistent with the absence of a public write-up, PoC, or third-party researcher credit and with the lack of confirmed exploitation.

Zoom bundled three companion high-severity, authenticated-local-only vulnerabilities into the same disclosure window, all of which require the attacker to already hold local, authenticated access to the Windows host -- a materially different (and lower-severity) trust boundary than CVE-2026-53412's unauthenticated network vector, but which combine with it to give an attacker a full initial-access-to-privilege-escalation chain if a target machine is compromised in stages:

- CVE-2026-53411 (CVSS 7.8, CWE-20 Improper Input Validation) -- affects the Zoom Workplace VDI Plugin for Windows before 6.6.14 (Zoom's own advisory language) / reported elsewhere as before 6.6.14 and 6.5.17 branches; allows an authenticated local user to escalate privileges. - CVE-2026-53410 (CVSS 7.0, CWE-367 Time-of-Check to Time-of-Use (TOCTOU) Race Condition) -- affects the install/uninstall routines shared across Zoom Workplace for Windows, the Windows VDI Client/Plugin, Zoom Rooms for Windows, and Remote Control for Zoom Contact Center; an authenticated local user can win a race during (un)installation to escalate privileges, a classic Windows installer-hijacking pattern (planting or swapping a file/service binary between a permission check and its use). - CVE-2026-53409 (CVSS 7.8, CWE-269 Improper Privilege Management) -- affects Zoom Rooms for Windows before 7.1.0; an authenticated local user can escalate privileges due to over-broad privilege assignment in the Rooms client/service.

Fixed versions per Zoom's bulletins and corroborating reporting: Zoom Workplace for Windows 7.0.0+ (account-takeover fix) / 7.0.5+ (TOCTOU fix); Windows VDI Client 6.5.18 / 6.6.15 / 7.0.10+ (branch-dependent); Zoom Rooms for Windows 7.1.0+ (privilege-management fix) / 7.0.5+ (TOCTOU fix); Zoom Workplace VDI Plugin 6.6.14+; Remote Control for Zoom Contact Center 7.0.0+. Organizations running any of these Windows clients should prioritize CVE-2026-53412 remediation given its unauthenticated, no-interaction, network-reachable profile, then apply the companion patches to close the local-privesc chain that could otherwise follow an initial foothold.

Given Zoom's massive installed base across enterprise, government, healthcare, and education sectors, and the fact that Zoom clients are frequently exposed to untrusted network segments (VDI pools, shared kiosks, BYOD-adjacent meeting rooms), this disclosure warrants tracking even absent confirmed exploitation: unauthenticated account-takeover primitives in ubiquitous collaboration software have historically drawn rapid reverse-engineering and exploit-development interest once patches ship (patch-diffing risk), and Zoom account compromise directly enables business-email-compromise-style social engineering, meeting hijacking, and downstream credential/data exposure.

MITRE ATT&CK techniques used in TL-2026-1405

Privilege Escalation

T1068 Exploitation for Privilege Escalation; T1548 Abuse Elevation Control Mechanism

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application

Discovery

T1082 System Information Discovery; T1518 Software Discovery

Execution

T1203 Exploitation for Client Execution

Defense Evasion

T1211 Exploitation for Stealth

Credential Access

T1212 Exploitation for Credential Access; T1528 Steal Application Access Token

Collection

T1213 Data from Information Repositories

Impact

T1499 Endpoint Denial of Service; T1531 Account Access Removal

Persistence

T1543 Create or Modify System Process

privilege-escalation

T1548 Abuse Elevation Control Mechanism

stealth

T1574 Hijack Execution Flow

Resource Development

T1587 Develop Capabilities

Reconnaissance

T1590 Gather Victim Network Information; T1595 Active Scanning

Affected products and versions in Zoom Patches Critical Windows Client Flaw (CVE-2026-53412

  • Zoom — Zoom Desktop Client for Windows (Zoom Workplace for Windows)
    Vulnerable versions: before 7.0.0; before 7.0.5
    Fixed in: 7.0.0 (CVE-2026-53412); 7.0.5 (CVE-2026-53410)
  • Zoom — Zoom VDI Client for Windows
    Vulnerable versions: before 6.5.18; before 6.6.15; before 7.0.10
    Fixed in: 6.5.18; 6.6.15; 7.0.10
  • Zoom — Zoom Workplace VDI Plugin for Windows
    Vulnerable versions: before 6.6.14
    Fixed in: 6.6.14
  • Zoom — Zoom Meeting SDK for Windows
    Vulnerable versions: before 7.0.0
    Fixed in: 7.0.0
  • Zoom — Zoom Rooms for Windows
    Vulnerable versions: before 7.1.0; before 7.0.5
    Fixed in: 7.1.0 (CVE-2026-53409); 7.0.5 (CVE-2026-53410)
  • Zoom — Remote Control for Zoom Contact Center
    Vulnerable versions: before 7.0.0
    Fixed in: 7.0.0

Remediation for Zoom Patches Critical Windows Client Flaw (CVE-2026-53412

Patches

  • Zoom Workplace for Windows 7.0.0+ / 7.0.5+
  • Zoom Meeting SDK for Windows 7.0.0+
  • Zoom Workplace VDI Client for Windows 6.5.18 / 6.6.15 / 7.0.10
  • Zoom Workplace VDI Plugin for Windows 6.6.14+
  • Zoom Rooms for Windows 7.1.0+ / 7.0.5+
  • Remote Control for Zoom Contact Center 7.0.0+

Immediate actions

  • Upgrade Zoom Workplace for Windows to 7.0.0 or later (CVE-2026-53412 fix) and to 7.0.5 or later (CVE-2026-53410 fix)
  • Upgrade Zoom Meeting SDK for Windows to 7.0.0 or later
  • Upgrade Zoom VDI Client for Windows to 6.5.18, 6.6.15, or 7.0.10 (branch-dependent) and Zoom Workplace VDI Plugin to 6.6.14 or later
  • Upgrade Zoom Rooms for Windows to 7.1.0 or later (CVE-2026-53409 fix) and to 7.0.5 or later (CVE-2026-53410 fix)
  • Upgrade Remote Control for Zoom Contact Center to 7.0.0 or later
  • Prioritize CVE-2026-53412 remediation on any Windows host running the affected Zoom clients that is reachable from untrusted or semi-trusted network segments

Workarounds

  • If immediate patching is not possible, restrict network reachability to vulnerable Zoom Windows clients (firewall/network segmentation) as a stopgap for CVE-2026-53412
  • Restrict local login/authenticated access to hosts running affected VDI/Rooms components to trusted administrators only, pending patching of the local-privesc CVEs

Longer-term hardening

  • Enforce automatic update policies for Zoom Windows clients via enterprise deployment tooling (SCCM/Intune/Zoom's MSI admin push) rather than relying on end-user self-update
  • Segment VDI pools and shared/kiosk Windows hosts running Zoom clients from untrusted network zones
  • Restrict local administrative rights on endpoints running Zoom Rooms / VDI clients to reduce the blast radius of local privilege-escalation chains
  • Maintain an inventory of Zoom client versions across the fleet to detect unpatched endpoints

CVEs associated with Zoom Patches Critical Windows Client Flaw (CVE-2026-53412

CVE-2026-53412, CVE-2026-53411, CVE-2026-53410, CVE-2026-53409

Weaknesses (CWE) in Zoom Patches Critical Windows Client Flaw (CVE-2026-53412

CWE-20, CWE-367, CWE-269

Timeline of Zoom Patches Critical Windows Client Flaw (CVE-2026-53412

  • Fixed builds ship: Zoom Workplace for Windows 7.0.0/7.0.5, VDI Client 6.5.18/6.6.15/7.0.10, VDI Plugin 6.6.14, Zoom Rooms for Windows 7.0.5/7.1.0, and Remote Control for Zoom Contact Center 7.0.0.
  • Zoom publishes four coordinated security bulletins (ZSB-26011, ZSB-26012, ZSB-26013, ZSB-26014) disclosing CVE-2026-53409, CVE-2026-53410, CVE-2026-53411, and CVE-2026-53412, with credit to Zoom's internal Offensive Security team.
  • Security media (BleepingComputer, BetaNews, TechRepublic, securityonline.info) publish coverage summarizing the four CVEs and urging immediate patching.
  • CVSS v3.1 base score of 9.8 (vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) for CVE-2026-53412 appears in third-party CVE trackers (e.g. Tenable).
  • CVE-2026-53412 is published in the NVD (nvd.nist.gov/vuln/detail/CVE-2026-53412), corroborating the CVSS v3.1 base score of 9.8 and additionally recording a CVSS v2 score of 10.0.
  • Zoom issues revision 1.1 of security bulletin ZSB-26014 (CVE-2026-53412), removing Zoom Meeting SDK for Windows from the affected-products list present in the original 1.0 publication -- narrowing the confirmed account-takeover exposure to Zoom Workplace for Windows and the Zoom Workplace VDI Client for Windows.
  • Threadlinqs Intelligence threat record TL-2026-1405 compiled from vendor bulletins, CVE trackers, and news coverage.
  • CISA Known Exploited Vulnerabilities catalog checked; none of the four CVEs (CVE-2026-53409/53410/53411/53412) are listed, consistent with vendor statements of no observed in-the-wild exploitation.
  • The Hacker News publishes coverage of the disclosure, which serves as the initial hunt source for this threat record.
  • NVD record for CVE-2026-53412 last modified, still in 'Awaiting Analysis' status with no change to CVSS scoring or affected-product data relative to the July 16 publication.

Update history for TL-2026-1405

Sources cited for Zoom Patches Critical Windows Client Flaw (CVE-2026-53412

Threats related to Zoom Patches Critical Windows Client Flaw (CVE-2026-53412

Detection coverage for TL-2026-1405

As of 2026-07-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1405 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats