Patch released Zoom Workplace privilege-escalation VDI Client Zoom auth-bypass
В Zoom для Windows исправили критическую уязвимость
CVE Tools coverage
Zoom has issued updates for its Windows-based applications and software development kits (SDKs) to address a critical vulnerability identified as CVE-2026-53412. This flaw could allow an unauthenticated attacker to remotely take over a victim's account, earning it a high CVSS score of 9.8. The issue was discovered internally by Zoom engineers and stems from improper input validation affecting Zoom Workplace, VDI Client, and Meeting SDK on Windows platforms. Additionally, the update resolves three other vulnerabilities rated between 7.0 and 7.8 on the CVSS scale, all related to privilege escalation risks.