[CIVN-2026-0374] Multiple Vulnerabilities in Zoom Products

By Published On: July 23, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple Vulnerabilities in Zoom Products


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: CRITICAL


Software Affected


Zoom Rooms for Windows before version 7.1.0

Zoom Workplace for Windows before version 7.0.5

Zoom Workplace VDI Client for Windows before versions 6.5.18, 6.6.15 and 7.0.10 in their respective branch

Zoom Workplace VDI plugin for Windows before versions 6.5.17 and 6.6.14 in their respective branch

Zoom Remote Control for Zoom Contact Center for Windows before version 7.0.0

Overview


Multiple vulnerabilities have been reported in Zoom products that could be exploited by an attacker to achieve privilege escalation and account takeover via network access.


Target Audience:

All end-user organisations and individuals using the affected versions of Zoom applications.


Risk Assessment:

Critical risk of unauthorized access, privilege escalation, and system compromise.


Impact Assessment:

Potential for bypassing security restrictions, privilege escalation, and account takeover.


Description


Zoom is a communications platform that provides video conferencing, team chat, phone services, whiteboard, mail, calendar, and other collaboration services for individuals and organisations.


Multiple vulnerabilities exist in Zoom products due to improper input validation, race conditions (time-of-check to time-of-use), and improper privilege management.


Successful exploitation of these vulnerabilities could allow an attacker to gain elevated privileges and account takeover via network access on the targeted system.


Solution


Apply appropriate updates as mentioned by the vendors given below:

https://www.zoom.com/en/trust/security-bulletin/zsb-26011/


https://www.zoom.com/en/trust/security-bulletin/zsb-26012/


https://www.zoom.com/en/trust/security-bulletin/zsb-26013/


https://www.zoom.com/en/trust/security-bulletin/zsb-26014/



Vendor Information


Zoom

https://www.zoom.com/en/trust/security-bulletin/


References


Zoom

https://www.zoom.com/en/trust/security-bulletin/zsb-26011/

https://www.zoom.com/en/trust/security-bulletin/zsb-26012/

https://www.zoom.com/en/trust/security-bulletin/zsb-26013/

https://www.zoom.com/en/trust/security-bulletin/zsb-26014/


CVE Name

CVE-2026-53409

CVE-2026-53410

CVE-2026-53411

CVE-2026-53412




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmpiKLkACgkQ3jCgcSdc

ys/SNg//bnyqjQnIlbgDolWd0OupN0DUx+ZGL54AStRZdMfU2JUgljixKOQZdc9+

SCMj3jOEjoyqCdcSj3J77n1sVcb56dcseKK3T2Ax1eBeXKhdDdeYsklHi16pfBVQ

mgJy4Qmwrei5if/s5G1YG6GA2zXxnLx3wGYbqVimINklroTCzHbYdIs1jTHxtVDP

tur3TkiVh9pNRBAcH9pvHTZwZS/EBDoaBQ6EfuOT09ewV7StMGRCFe1v9kNiFIyH

HF25AsM7Q6y1IbxNOyl1kwLdQOTYCL0O5ibOqdrvI9A2Au6dZgrbn6OzzpJbEiAO

wsgyWHoKsbQ8Q3FZqM6+Vetp+QGQEs5AOyVe8vRknao9FGBnEcxnlItF+s9dtizO

EivT2U+KML2rkokjpXcKOoFpNXBgsolHTSaeUc0/ku/fVCNEtyOgBrs5OhkNyzJU

pXUwLwBCxs2C2iQzuxlkKAuExa23FujFXWiYGLmPEBHckVN7ulkp9ob+/xfe9oU/

9rJyHeHApX7Z2DUnBPnmmhQ+Pu2u/83ErKDDuTFNGLFVPn3Lfk5xC0VG/DK762Nt

YcPrrAlkMnjbuhCr0xGB8od7VkBzM/pJoeepc2Ym7qZKH57KrYmO1RL9u/i+0/bh

Fd70IfWMm+kqXFv+DNA6yeuSnkug1p7G3cd7V/05x8VTuXE8jQQ=

=1Pri

—–END PGP SIGNATURE—–

Share this article