VDB
CVE-2026-53412
CVE-2026-53412
PUBLISHED
CVSS 9.8 CRITICAL
Reported by Zoom · Published July 16, 2026
Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an account takeover via network access.
Risk Scores
CVSS 3.1
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zoom Communications | Zoom Workplace for Windows | 0 |
| Zoom Communications | Zoom Workplace for Windows | 0, 0 |
Timeline
- Jan 1, 2026 CVE Published
- Jul 17, 2026 CVE Updated