PatchSiren

Zoom Communications CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Zoom Communications CVE published 2026-08-11

CVE-2026-53414

The CVE-2026-53414 vulnerability is related to a missing bounds check in the annotator function of Zoom Clients, which allows for a buffer over-read. This may enable a meeting participant to conduct a denial of service on another participant via network access. Organizations should review and apply security updates to mitigate potential impacts. The vulnerability has a CVSS score of 6.5 and a CVSS severit [truncated]

HIGH Zoom Communications CVE published 2026-08-11

CVE-2026-53413

The CVE-2026-53413 record describes a missing bounds check in the annotator function of Zoom Clients, which may allow a meeting participant to achieve remote code execution of another participant via network access. This vulnerability has a CVSS score of 8.3 and is classified as HIGH severity. Organizations and users of Zoom Clients should be aware of this vulnerability and take steps to mitigate the risk [truncated]

CRITICAL Zoom Communications CVE published 2026-07-16

CVE-2026-53412

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-16T22:17:31.380Z and has not been modified since then. This CRITICAL vulnerability with a CVSS score of 9.8 involves Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows. It may allow an unauthenticated user to conduct an account [truncated]

HIGH Zoom Communications CVE published 2026-07-16

CVE-2026-53411

CVE-2026-53411 is a high-severity vulnerability in Zoom Clients for Windows, classified as a time-of-check to time-of-use (TOCTOU) race condition. This vulnerability could allow an authenticated local user to escalate privileges during the installation and uninstallation process of certain Zoom Clients for Windows. The CVE record was published on 2026-07-16T22:17:31.267Z and has not been modified since th [truncated]

HIGH Zoom Communications CVE published 2026-07-16

CVE-2026-53410

A time-of-check to time-of-use (TOCTOU) race condition was found in the installation and uninstallation process of certain Zoom Clients for Windows. This vulnerability, identified as CVE-2026-53410, could allow an authenticated local user to escalate privileges. The issue arises during the installation and uninstallation process, potentially impacting users of Zoom Clients for Windows. The vulnerability's [truncated]

HIGH Zoom Communications CVE published 2026-07-16

CVE-2026-53409

CVE-2026-53409 is a HIGH severity vulnerability in Zoom Rooms for Windows before version 7.1.0. It is caused by improper privilege management, which may allow an authenticated user to conduct an escalation of privilege via local access. The CVSS score for this vulnerability is 7.8. Users of Zoom Rooms for Windows before version 7.1.0 should apply the patch to prevent potential privilege escalation attacks [truncated]

HIGH Zoom Communications CVE published 2026-06-12

CVE-2026-53408

CVE-2026-53408 is a HIGH severity vulnerability with a CVSS score of 8.1. The vulnerability exists in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS. An unauthenticated user may conduct an escalation of privilege via network access due to improper authorization in the handler for custom URL schemes.

HIGH Zoom Communications CVE published 2026-06-12

CVE-2026-53407

CVE-2026-53407 is a HIGH-severity vulnerability (CVSS Score: 8.1) affecting Zoom Workplace. The vulnerability is caused by improper authorization in the handler for custom URL schemes in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS. This vulnerability may allow an unauthenticated user to conduct an escalation of privilege via network access.

HIGH Zoom Communications CVE published 2026-06-12

CVE-2026-53406

CVE-2026-53406 is a high-severity vulnerability (CVSS Score: 7.8) affecting Zoom Contact Center for Windows before version 7.0.0. The vulnerability is caused by insufficient verification of data authenticity in the remote control feature, which may allow an authenticated user to enable an escalation of privilege via local access.