Popular video conferencing service Zoom Video Communications has resolved 4 security vulnerabilities (CVE-2026-53409, CVE-2026-53410, CVE-2026-53411, CVE-2026-53412) in Zoom products. A malicious actor could exploit these vulnerabilities to trigger elevation of privilege on the targeted system. Issues affect the products below:
- Zoom Rooms for Windows before version 7.1.0;
- Zoom Workplace for Windows before version 7.0.5;
- Zoom Workplace VDI Client for Windows before versions 6.5.17 and 6.6.14 in their respective branch;
- Zoom Workplace VDI Plugin for Windows before versions 6.5.17 and 6.6.14 in their respective branch;
- Zoom Rooms for Windows before version 7.0.5;
- Remote Control for Zoom Contact Center for Windows before version 7.0.0;
- Zoom Workplace VDI Plugin for Windows before version 6.6.14;
- Zoom Workplace for Windows before version 7.0.0;
- Zoom Workplace VDI Client for Windows before versions 7.0.10, 6.6.15 and 6.5.18 in their respective branch.
More information on vulnerabilities and updates is available in Zoom security bulletins – zoom.us.