
[CIVN-2026-0423] Multiple Vulnerabilities in Zoom Products
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in Zoom Products
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
Zoom Workplace (all supported platforms) before versions 7.1.5 and 7.0.6 in their respective branches
Zoom Workplace VDI Client for Windows before versions 7.0.11 and 6.6.16 in their respective branches
Zoom Workplace VDI Plugin for Windows before versions 7.0.11 and 6.6.16 in their respective branches
Zoom Rooms (all supported platforms) before version 7.1.5
Zoom Meeting SDK (all supported platforms) before version 7.1.5
Zoom Video SDK all supported platforms before version 2.6.5
Overview
Multiple vulnerabilities have been reported in Zoom products that could allow a remote attacker to execute arbitrary code, cause a denial of service (DoS), and gain access to sensitive information on the targeted system.
Target Audience:
All end-user organisations and individuals using the affected versions of Zoom applications.
Risk Assessment:
High risk of remote code execution, denial of service, and unauthorized information disclosure.
Impact Assessment:
Potential for complete compromise.
Description
Zoom is a communications platform that provides video conferencing, team chat, and other collaboration services for individuals and organisations.
Multiple vulnerabilities exist in Zoom products due to memory corruption and path traversal issues.
Successful exploitation of these vulnerabilities could allow an attacker to execute remote code, cause a denial of service (DoS), and perform information disclosure on targeted systems.
Solution
Apply appropriate updates as mentioned by the vendor:
https://www.zoom.com/en/trust/security-bulletin/zsb-26015/
https://www.zoom.com/en/trust/security-bulletin/zsb-26016/
https://www.zoom.com/en/trust/security-bulletin/zsb-26017/
https://www.zoom.com/en/trust/security-bulletin/zsb-26018/
Vendor Information
Zoom
https://www.zoom.com/en/trust/security-bulletin/
References
Zoom
https://www.zoom.com/en/trust/security-bulletin/zsb-26015/
https://www.zoom.com/en/trust/security-bulletin/zsb-26016/
https://www.zoom.com/en/trust/security-bulletin/zsb-26017/
https://www.zoom.com/en/trust/security-bulletin/zsb-26018/
CVE Name
CVE-2026-53413
CVE-2026-53414
CVE-2026-53415
CVE-2026-53416
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqVivcACgkQ3jCgcSdc
ys+NOQ//WC/hEOk26DzLh4aa8z1u+cyVSAOEViPbQNk83mu6xsXI/dtbP7wREP7a
dt28sEM7/Da0Yv6mt9VRRNsvxj6jX0nI4yF+fw9nynubSOKJOCo6BwRNl1Pbalhc
2GJx4heS0slKmhCXkEK63gxd1y5Mi3O8ZCtR4w+396CRBOopmQEcz8WiYw6q1o4D
BEtaX/Rl5mzpuZk4vj1cC2K5AO18N35ejMhgYL74fKXBJ8te2O6oN8zbNhOvPF2J
krUbSlx/CvwjkeyGj2Ymn3inOtdkpkrnUwFriUNfquHLBRCgexUUgBQXDo4jv3uJ
iCVRDgKQ4Yuo44QjvJ7I4F7MrLWZ8RRNZlC3B4484Ze6Lu/ffii2tCSBFQuwNhn/
NnJBH+k83yDqM+FJxIvLlNtnN9Rw0md9q7nhkUfZUA7kdgq4CuAGbogcwWkFm83Z
WsuX3n5FDyR9pV7ljxen2+VLP1U7M0oFtC/DMv+ULN1/vY1A3u31QI9scDBoDPeU
ZBCAjvEHu1lpOZcviuO9g5NP/PYrWzEgSRAR5UCtQJcbyLpZ/IvyufISkUcXkK8J
TAQFUfDfwr4ftQY+pIkWvgP/3gvV3/lqj7SGHo0NA1W+kYC9Wr1rkJ/yDbLHWaB5
Xhp4CEQWgsaM/wiimbQ/9+tMNwrUbIbFr9t0OSjBhrG2rFZX31c=
=Jc/k
—–END PGP SIGNATURE—–


