Zoom Communications Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with Zoom Communications products.
Products
- Zoom Clients4 vulnerabilities
- Zoom Workplace4 vulnerabilities
- Zoom Rooms2 vulnerabilities
- Zoom Workplace VDI Plugin2 vulnerabilities
- Remote Control for Zoom Contact Center1 vulnerability
- Zoom VDI1 vulnerability
- Zoom Workplace for Windows1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-53416HIGH | Zoom VDI - Path TraversalPath traversal in Zoom VDI Client and Plugins may allow an authenticated user to conduct information disclosure via local access. CWE-23Aug 11, 2026 | CVSS7.1v3.1 | EPSS0.17% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-53415HIGH | Zoom Clients - Use After FreeUse after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve remote code execution of another participant via network access. CWE-416Aug 11, 2026 | CVSS8.3v3.1 | EPSS0.388% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-53414MEDIUM | Zoom Clients - Buffer Over-readMissing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting participant to conduct a denial of service on another participant via network access. CWE-126Aug 11, 2026 | CVSS6.5v3.1 | EPSS0.276% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-53413HIGH | Zoom Clients - Buffer Over-writeMissing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting participant to achieve remote code execution of another participant via network access. CWE-787Aug 11, 2026 | CVSS8.3v3.1 | EPSS0.409% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-53412CRITICAL | Zoom Workplace VDI Plugin for Windows - Improper Input ValidationImproper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an account takeover via network access. CWE-20Jul 16, 2026 | CVSS9.8v3.1 | EPSS0.647% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-53411HIGH | Zoom Workplace VDI Plugin for Windows - Improper Input ValidationA time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to escalate privileges. CWE-20Jul 16, 2026 | CVSS7.8v3.1 | EPSS0.132% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-53410HIGH | Zoom Clients for Windows - Race ConditionA time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to escalate privileges. CWE-367Jul 16, 2026 | CVSS7.0v3.1 | EPSS0.094% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-53409HIGH | Generated title:Zoom Rooms for Windows Improper Privilege Management Local Privilege EscalationImproper Privilege Management in Zoom Rooms for Windows before version 7.1.0 may allow an authenticated user to conduct an escalation of privilege via local access. CWE-20Jul 16, 2026 | CVSS7.8v3.1 | EPSS0.152% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-53408HIGH | Generated title:Zoom Workplace Custom URL Scheme Improper Authorization Leading to Privilege EscalationImproper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access. CWE-939Jun 12, 2026 | CVSS8.1v3.1 | EPSS0.211% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-53407HIGH | Generated title:Zoom Workplace Custom URL Scheme Improper AuthorizationImproper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access. CWE-939Jun 12, 2026 | CVSS8.1v3.1 | EPSS0.231% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-53406HIGH | Generated title:Zoom Remote Control for Zoom Contact Center Insufficient Verification of Data Authenticity Privilege EscalationInsufficient Verification of Data Authenticity in Remote Control for Zoom Contact Center for Windows before version 7.0.0 may allow an authenticated user to enable an escalation of privilege via local access. CWE-345Jun 12, 2026 | CVSS7.8v3.1 | EPSS0.08% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-30906HIGH | Generated title:Zoom Rooms for Windows Installer Untrusted Search Path Privilege EscalationUntrusted search path in the installer for Zoom Rooms for Windows before version 7.0.0 may allow an authenticated user to enable an escalation of privilege via local access. CWE-426May 13, 2026 | CVSS7.8v3.1 | EPSS0.118% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-30905HIGH | Generated title:Zoom Workplace VDI Plugin Windows Universal Installer External Control of File Name or Path Privilege EscalationExternal Control of File Name or Path in the Zoom Workplace VDI Plugin Windows Universal Installer before version 6.6.11 may allow an authenticated user to conduct an escalation of privilege via local access. | CVSS7.8v3.1 | EPSS0.118% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Generated title:Zoom Workplace for iOS Protection Mechanism Failure Information Disclosure via Physical AccessProtection Mechanism Failure in Zoom Workplace for iOS before version 7.0.0 may allow an authenticated user to conduct a disclosure of information via physical access. CWE-693May 13, 2026 | CVSS1.8v3.1 | EPSS0.143% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-30903CRITICAL | Generated title:Zoom Workplace for Windows Mail Feature External Control of File Name or Path Privilege EscalationExternal Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via network access. | CVSS9.6v3.1 | EPSS0.328% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |