
Zoom rolls out urgent Windows patches to block account takeover and privilege escalations
Zoom released security updates for Windows to fix a critical flaw (CVE-2026-53412, CVSS 9.8) in Zoom Workplace for Windows and related VDI components that could allow an unauthenticated attacker to take over accounts via network. The patch also addresses three high-severity issues (CVE-2026-53411, CVE-2026-53410, CVE-2026-53409) that could enable privilege escalation for authenticated users or via local access across Zoom Workplace, VDI, VDI plugin, and Zoom Rooms for Windows. Affected version details are provided for each product, and Zoom notes no active exploitation so far. The update also removes Meeting SDK for Windows from the affected scope. Users should install the latest versions to stay protected.









