← All CVEs

CVE-2026-53412

critical · 9.8

Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an account takeover via network access.

9.8
CVSS
0.6%
EPSS (exploit prob.)
50th
EPSS percentile
2026-07-16
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
zoomworkplace_desktop< 7.0.0
zoomworkplace_virtual_desktop_infrastructure>= 6.5.0, < 6.5.18
zoomworkplace_virtual_desktop_infrastructure>= 6.6.0, < 6.6.15
zoomworkplace_virtual_desktop_infrastructure>= 7.0.0, < 7.0.10

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2026-53412