Vulnerability Intelligence Report
CVE-2026-30903
External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via network access.
No Active Exploit Signals
CVSS Base Score
9.6
CRITICAL
Exploitability:2.9
Impact Score:6.1
EPSS Probability:0.33%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-73 ↗CWE-73 External control of file name or path
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Zoom Communications | Zoom Workplace | see references (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.328%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Zoom Communications, Inc. · Vendor · USA |
| Reserved | 2026-03-06T18:44:57 |
| Published | 2026-03-11T14:52:55 |
| Patch Date | 2026-03-10 |
| Last Updated | 2026-03-12T03:55:33 |
Community Chatter & Buzz