Zoom: critical flaw (9.8) allowing account takeover on Windows

Zoom fixed a vulnerability scored 9.8 out of 10: an unauthenticated attacker could take over the account over the network. It’s CVE-2026-53412, affecting Zoom Workplace for Windows below version 7.0.0.

Zoom found it internally and says there are no signs of exploitation yet. That’s exactly why now is the good moment: update quietly, before the first campaign appears.

  • Open Zoom → profile picture → “Check for Updates”; it should read 7.0.0 or newer.
  • If you use Zoom Rooms or the VDI client, check those separately — they have their own fixed versions.
  • Send a short message to the team; across 20 machines, “update your Zoom” means 20 people who have to remember.

Sources

This article was generated with AI assistance.

We keep track of updates for you

← All news