Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-53412: Zoom Workplace VDI Plugin for Windows - Unauthenticated Account Takeover
CVE-2026-53412
CVE-2026-53412
Summary
The Zoom Workplace VDI Plugin for Windows has a security weakness that could allow an unauthorized user to access and take control of a user's account through the network. This is a serious issue because it could lead to unauthorized access to sensitive information and disruption of business operations. To protect your business, update your Zoom Workplace VDI Plugin for Windows to the latest version as soon as possible.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| zoom communications | zoom workplace for windows | < 7.0.0 |
Original title
Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an account takeover via netw...
Original description
Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an account takeover via network access.
mitre CVSS3.1
9.8
Vulnerability type
CWE-20
Improper Input Validation
Published: 16 Jul 2026 · Updated: 17 Jul 2026 · First seen: 16 Jul 2026