Visualização normal

Antes de ontemStream principal
  • ✇Cybersecurity News
  • Zoom Patches Four Security Flaws, Including Two Remote Code Execution Bugs Do Son
    Zoom patched four security vulnerabilities, including two remote code execution bugs in the annotator function. Update your Zoom clients now. Related Posts: Zero-Click File Drop Hits Xiaomi ShareMe: PoC Public CVE-2026-65640: WordPress 7.0.4 Fixes Remote Code Execution MariaDB Low-Privilege Remote Code Execution Chain: Full Details and PoC Exploit Code Publicly Disclosed The post Zoom Patches Four Security Flaws, Including Two Remote Code Execution Bugs appeared first on Daily CyberSecurity.
     
  • ✇Security Affairs
  • Zoom Fixes CVE-2026-53412, a Critical Account Takeover Bug Pierluigi Paganini
    Zoom warns of a critical Windows flaw, tracked as CVE-2026-53412, that could let attackers take over accounts without authentication. Zoom has fixed a critical Windows vulnerability, tracked as CVE-2026-53412 (CVSS score of 9.8) that could allow unauthenticated attackers to hijack user accounts. The flaw affects older versions of Workplace, the Windows VDI Client, and the Meeting SDK for Windows. “Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows,
     

Zoom Fixes CVE-2026-53412, a Critical Account Takeover Bug

16 de Julho de 2026, 04:36

Zoom warns of a critical Windows flaw, tracked as CVE-2026-53412, that could let attackers take over accounts without authentication.

Zoom has fixed a critical Windows vulnerability, tracked as CVE-2026-53412 (CVSS score of 9.8) that could allow unauthenticated attackers to hijack user accounts. The flaw affects older versions of Workplace, the Windows VDI Client, and the Meeting SDK for Windows.

“Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an account takeover via network access.” reads the advisory.

The company Offensive Security team discovered the vulnerability. The company did not provide technical details about the vulnerability.

The company also addressed the following vulnerabilities:

  • CVE-2026-53410 (CVSS score of 8.8) – A race condition in Zoom Workplace, VDI Client/Plugin, Rooms, and Remote Control for Zoom Contact Center on Windows could let an authenticated local user gain higher privileges during installation or uninstallation.
  • CVE-2026-53409 (CVSS score of 8.8) – An improper privilege management flaw in Rooms for Windows could let an authenticated local user escalate privileges.
  • CVE-2026-53411 (CVSS score of 8.8) – An input validation flaw in the Workplace VDI Plugin for Windows could let an authenticated local user gain elevated privileges.

Users should update to the latest versions as soon as possible.

None of the above issues is currently under active exploitation in the wild.

In January, the Cloud-based video conferencing and online collaboration platform released security updates to address multiple vulnerabilities, including command injection, tracked as CVE-2026-22844 (CVSS score of 9.9), in Node Multimedia Routers (MMRs) that could result in remote code execution.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Zoom)

❌
❌