CRITICAL
Zoom Patches Critical Windows Flaw Enabling Account Takeover
Zoom patched a critical improper input validation flaw, tracked as CVE-2026-53412 (CVSS 9.8), affecting the Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows. The vulnerability could facilitate account takeover. Given the near-maximum CVSS score and broad reach across Zoom’s Windows client lineup, affected organizations should prioritize updating to the patched release.