Vulnerability Intelligence Report
Zoom Workplace VDI Plugin for Windows - Improper Input Validation
CVE-2026-53412
Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an account takeover via network access.
No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:0.51%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-20 ↗CWE-20 Improper input validation
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Zoom Communications | Zoom Workplace for Windows | 0 < 7.0.0 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.508%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Zoom Communications, Inc. · Vendor · USA |
| Reserved | 2026-06-09T10:18:05 |
| Published | 2026-07-16T21:15:25 |
| Patch Date | 2026-07-14 |
| Last Updated | 2026-07-17T13:18:46 |
Community Chatter & Buzz