[CIVN-2026-0423] Multiple Vulnerabilities in Zoom Products

By Published On: August 31, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple Vulnerabilities in Zoom Products


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: CRITICAL


Software Affected


Zoom Workplace (all supported platforms) before versions 7.1.5 and 7.0.6 in their respective branches

Zoom Workplace VDI Client for Windows before versions 7.0.11 and 6.6.16 in their respective branches

Zoom Workplace VDI Plugin for Windows before versions 7.0.11 and 6.6.16 in their respective branches

Zoom Rooms (all supported platforms) before version 7.1.5

Zoom Meeting SDK (all supported platforms) before version 7.1.5

Zoom Video SDK all supported platforms before version 2.6.5

Overview


Multiple vulnerabilities have been reported in Zoom products that could allow a remote attacker to execute arbitrary code, cause a denial of service (DoS), and gain access to sensitive information on the targeted system.


Target Audience:

All end-user organisations and individuals using the affected versions of Zoom applications.


Risk Assessment:

High risk of remote code execution, denial of service, and unauthorized information disclosure.


Impact Assessment:

Potential for complete compromise.


Description


Zoom is a communications platform that provides video conferencing, team chat, and other collaboration services for individuals and organisations.


Multiple vulnerabilities exist in Zoom products due to memory corruption and path traversal issues.


Successful exploitation of these vulnerabilities could allow an attacker to execute remote code, cause a denial of service (DoS), and perform information disclosure on targeted systems.


Solution


Apply appropriate updates as mentioned by the vendor:

https://www.zoom.com/en/trust/security-bulletin/zsb-26015/


https://www.zoom.com/en/trust/security-bulletin/zsb-26016/


https://www.zoom.com/en/trust/security-bulletin/zsb-26017/


https://www.zoom.com/en/trust/security-bulletin/zsb-26018/



Vendor Information


Zoom

https://www.zoom.com/en/trust/security-bulletin/


References


Zoom

https://www.zoom.com/en/trust/security-bulletin/zsb-26015/

https://www.zoom.com/en/trust/security-bulletin/zsb-26016/

https://www.zoom.com/en/trust/security-bulletin/zsb-26017/

https://www.zoom.com/en/trust/security-bulletin/zsb-26018/


CVE Name

CVE-2026-53413

CVE-2026-53414

CVE-2026-53415

CVE-2026-53416




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqVivcACgkQ3jCgcSdc

ys+NOQ//WC/hEOk26DzLh4aa8z1u+cyVSAOEViPbQNk83mu6xsXI/dtbP7wREP7a

dt28sEM7/Da0Yv6mt9VRRNsvxj6jX0nI4yF+fw9nynubSOKJOCo6BwRNl1Pbalhc

2GJx4heS0slKmhCXkEK63gxd1y5Mi3O8ZCtR4w+396CRBOopmQEcz8WiYw6q1o4D

BEtaX/Rl5mzpuZk4vj1cC2K5AO18N35ejMhgYL74fKXBJ8te2O6oN8zbNhOvPF2J

krUbSlx/CvwjkeyGj2Ymn3inOtdkpkrnUwFriUNfquHLBRCgexUUgBQXDo4jv3uJ

iCVRDgKQ4Yuo44QjvJ7I4F7MrLWZ8RRNZlC3B4484Ze6Lu/ffii2tCSBFQuwNhn/

NnJBH+k83yDqM+FJxIvLlNtnN9Rw0md9q7nhkUfZUA7kdgq4CuAGbogcwWkFm83Z

WsuX3n5FDyR9pV7ljxen2+VLP1U7M0oFtC/DMv+ULN1/vY1A3u31QI9scDBoDPeU

ZBCAjvEHu1lpOZcviuO9g5NP/PYrWzEgSRAR5UCtQJcbyLpZ/IvyufISkUcXkK8J

TAQFUfDfwr4ftQY+pIkWvgP/3gvV3/lqj7SGHo0NA1W+kYC9Wr1rkJ/yDbLHWaB5

Xhp4CEQWgsaM/wiimbQ/9+tMNwrUbIbFr9t0OSjBhrG2rFZX31c=

=Jc/k

—–END PGP SIGNATURE—–

Share this article