Input validation error in Zoom Video Communications, Inc. products - CVE-2026-53412

 

Input validation error in Zoom Video Communications, Inc. products - CVE-2026-53412

Published: July 14, 2026


Vulnerability identifier: #VU137494
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-53412
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to conduct an account takeover.

The vulnerability exists due to improper input validation in Zoom Meeting SDK for Windows when handling network requests. A remote attacker can send crafted input to conduct an account takeover.


Affected software

Zoom Workplace VDI Plugin for Windows
Zoom Meeting SDK for Windows
Zoom Workplace Desktop App for Windows

How to mitigate CVE-2026-53412

Install security update from vendor's website.

Zoom Workplace VDI Plugin for Windows - addressed in versions 6.5.18, 6.6.15, 7.0.10
Zoom Meeting SDK for Windows - update to 7.0.0
Zoom Workplace Desktop App for Windows - update to 7.0.0 33767

External References

Related Security Bulletins