Zoom disclosed a critical security vulnerability in its Windows-based applications. This flaw allows unauthenticated attackers to take over user accounts remotely.

Security experts tracked the issue as CVE-2026-53412. The vulnerability carries a severity score of 9.8 out of 10.

The issue stems from improper input validation. Affected products include the Zoom Workplace client, the VDI Client, and the Meeting SDK for Windows.

Zoom discovered the flaw internally and released patches to address the risk. The company urges users and administrators to update to the latest versions immediately.

No evidence currently suggests that attackers have exploited the vulnerability in the wild.