Input validation error in Zoom Video Communications, Inc. products - CVE-2026-53412
Published: July 14, 2026
Vulnerability identifier: #VU137494
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-53412
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to conduct an account takeover.
The vulnerability exists due to improper input validation in Zoom Meeting SDK for Windows when handling network requests. A remote attacker can send crafted input to conduct an account takeover.
Affected software
Zoom Workplace VDI Plugin for Windows
Zoom Meeting SDK for Windows
Zoom Workplace Desktop App for Windows
Zoom Meeting SDK for Windows
Zoom Workplace Desktop App for Windows
How to mitigate CVE-2026-53412
Install security update from vendor's website.
Zoom Workplace VDI Plugin for Windows - addressed in versions 6.5.18, 6.6.15, 7.0.10
Zoom Meeting SDK for Windows - update to 7.0.0
Zoom Workplace Desktop App for Windows - update to 7.0.0 33767
Zoom Meeting SDK for Windows - update to 7.0.0
Zoom Workplace Desktop App for Windows - update to 7.0.0 33767