# Zoom Communications vulnerabilities & exploitation

> As of 2026-10-05, Threadlinqs tracks 5 Zoom Communications CVEs, 0 in the CISA Known Exploited Vulnerabilities catalog, linked to 4 tracked threat campaigns.

**Data as of:** 2026-10-05

## Exploitation timeline

Threadlinqs has recorded 5 Zoom Communications CVEs published between 2026-07-15 and 2026-08-15. The busiest month was 2026-07 (4 new CVEs). None of them is listed in CISA KEV yet.

## Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 5 of 5 tracked Zoom Communications CVEs.

- [CVE-2026-53413](https://intel.threadlinqs.com/cve/CVE-2026-53413) — HIGH 8.3 · EPSS 0.4% · 2026-08-11
- [CVE-2026-53412](https://intel.threadlinqs.com/cve/CVE-2026-53412) — CRITICAL 9.8 · 2026-07-16
- [CVE-2026-53409](https://intel.threadlinqs.com/cve/CVE-2026-53409) — HIGH 7.8 · 2026-07-16
- [CVE-2026-53411](https://intel.threadlinqs.com/cve/CVE-2026-53411) — HIGH 7.8 · 2026-07-16
- [CVE-2026-53410](https://intel.threadlinqs.com/cve/CVE-2026-53410) — HIGH 7 · 2026-07-16

## Products affected

Threadlinqs normalises CPE and CNA product records across all 5 CVEs; 4 distinct Zoom Communications products are affected. The most frequently affected:

- Zoom Clients — 2 CVEs
- Zoom Rooms — 1 CVE
- Zoom Workplace VDI Plugin — 1 CVE
- Zoom Workplace for Windows — 1 CVE

## Threat activity

4 tracked threat campaigns reference Zoom Communications products or exploit Zoom Communications CVEs:

- ["Zoomsday" Flaws (CVE-2026-53413, CVE-2026-53414, CVE-2026-53415) Let One Zoom Meeting Participant Attack Another](https://intel.threadlinqs.com/threat/TL-2026-2001) — CRITICAL — 2026-08-12
- [Zoom Windows Apps Critical Unauthenticated Account Takeover (CVE-2026-53412) Plus Three Chained Local Privilege Escalation Flaws](https://intel.threadlinqs.com/threat/TL-2026-1393) — CRITICAL — 2026-07-16
- [Zoom Patches Critical Windows Client Flaw (CVE-2026-53412, CVSS 9.8) Enabling Unauthenticated Account Takeover](https://intel.threadlinqs.com/threat/TL-2026-1405) — CRITICAL — 2026-07-16
- [CVE-2026-53412: Unauthenticated Remote Account Takeover in Zoom Desktop Client, VDI Client, and Meeting SDK for Windows](https://intel.threadlinqs.com/threat/TL-2026-1407) — CRITICAL — 2026-07-16

## How to prioritise Zoom Communications patching

This order follows the data Threadlinqs holds for Zoom Communications, not a generic severity checklist:

- No Zoom Communications CVE is in CISA KEV yet, so rank by exploit probability instead.
- Outside KEV, the highest EPSS scores are [CVE-2026-53413](https://intel.threadlinqs.com/cve/CVE-2026-53413) (0.4%).
- 1 CVE scores Critical and 4 High on CVSS v3 (maximum 9.8, average 8.1); sequence these after KEV and high-EPSS items.

## About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.

Canonical: https://intel.threadlinqs.com/vendors/zoom-communications
All vendors: https://intel.threadlinqs.com/vendors
Full detection coverage and IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
