Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-53412: Zoom Workplace VDI Plugin for Windows - Unauthenticated Account Takeover

CVE-2026-53412 CVE-2026-53412
Summary

The Zoom Workplace VDI Plugin for Windows has a security weakness that could allow an unauthorized user to access and take control of a user's account through the network. This is a serious issue because it could lead to unauthorized access to sensitive information and disruption of business operations. To protect your business, update your Zoom Workplace VDI Plugin for Windows to the latest version as soon as possible.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
zoom communications zoom workplace for windows < 7.0.0
Original title
Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an account takeover via netw...
Original description
Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an account takeover via network access.
mitre CVSS3.1 9.8
Vulnerability type
CWE-20 Improper Input Validation
Published: 16 Jul 2026 · Updated: 17 Jul 2026 · First seen: 16 Jul 2026