Zoom has patched a critical vulnerability, tracked as CVE-2026-53412 and rated 9.8 out of 10 on the CVSS scale, in the Zoom Desktop Client for Windows and the Zoom VDI Client for Windows. The flaw is an improper input validation issue that allows an unauthenticated attacker with network access to take over a user’s account. No existing Zoom credentials, no local access to the victim’s machine and no action from the victim are required, which is about as favourable a combination as an attacker can ask for.
Why the “unauthenticated, zero-click” combination matters
Most account takeover vulnerabilities require at least one piece of leverage: a stolen password, a phishing click, physical proximity, or an already-compromised session. CVE-2026-53412 requires none of those. An attacker only needs network access to a target running an affected Zoom client, low attack complexity, and the ability to send crafted network traffic. Once exploited, the attacker can impersonate the affected user, which opens the door to their meetings, chat history, shared content and any account-linked resources. For an organisation running Zoom across a distributed European workforce, that is a route into internal conversations and shared files that bypasses every access control built around requiring a login.
What is affected, and what is not
The vulnerability affects Zoom Workplace for Windows before version 7.0.0, the Windows VDI Client before versions 7.0.10, 6.6.15 and 6.5.18, and, in an earlier revision of the advisory, the Meeting SDK for Windows before 7.0.0. Zoom subsequently revised the advisory on July 15, 2026 to remove the Meeting SDK for Windows from the affected product list, so organisations that embed the SDK should confirm the current advisory rather than relying on the initial version. Zoom also patched three high-severity privilege escalation issues in the same release cycle. As of publication, there is no confirmed evidence of exploitation in the wild, which is exactly the window in which patching is cheap and a breach is not.
What to do this week
Every Windows endpoint running Zoom Workplace or the VDI Client needs to be updated to the patched versions, and this is not a rollout that should wait for the next scheduled patch cycle given the severity and the unauthenticated attack path. IT and security teams should confirm their endpoint management tooling can report which machines are still on a vulnerable build, since “we pushed the update” and “every laptop actually installed it” are frequently two different facts. Organisations that manage Zoom through a VDI or virtual desktop environment should treat that fleet as a priority, since a single unpatched golden image can leave an entire pool of desktops exposed at once.
If you need help verifying patch compliance across your Windows and VDI estate, or want a broader review of how quickly your organisation can detect and remediate a critical vulnerability like this one, contact Excello Digital. We help European IT teams close the gap between a vendor’s patch release and full deployment across every affected machine.
