Cyber Cookie mascotCyber Cookie
Menu ▾
CVE-2026-53412
criticalCVSS 9.8

Zoom Desktop Client for Windows (versions before 6.3.10)

Zoom is the video conferencing and online meetings platform used by hundreds of millions of people worldwide for work calls, webinars, and remote collaboration.

Reported in Issue #37Japan's Food Chain Hit, Zoom Needs Patching Now

Root Cause

The application does not properly validate input received over the network before processing it. Think of it like a reception desk that waves through anyone claiming to be a guest without checking their name against the list — and then hands them a master key.

Attack Vector

An attacker with network access sends malformed input to the Zoom client. Because the application does not verify what it receives, the attacker can manipulate the client's behaviour, ultimately gaining control of the account. No interaction from the victim is required beyond having Zoom running.

Recommended Actions

  1. Open Zoom and update to the latest version immediately via Help → Check for Updates.
  2. If you manage Zoom across an organisation, push the update via your MDM or endpoint management platform today.
  3. Monitor for any unexpected account activity or unauthorised sessions in your Zoom admin console.