Zoom has patched a critical, unauthenticated account takeover flaw in its Windows client, a reminder that the collaboration tools sitting on nearly every enterprise endpoint are now squarely part of the identity attack surface.

Zoom’s own security bulletin, ZSB-26014, discloses CVE-2026-53412, a 9.8-rated critical vulnerability caused by improper input validation in the Zoom Desktop Client for Windows and the Zoom VDI Client for Windows. The flaw lets an unauthenticated attacker with network access take over an account, with no user interaction required. Zoom fixed it in Workplace for Windows version 7.0.0 and later, and in VDI Client versions 7.0.10, 6.6.15, and 6.5.18. The bulletin credits Zoom’s own internal offensive security team with finding the issue, and Zoom has not indicated any evidence of exploitation in the wild.

The severity here matters less for what an attacker could do inside a single Zoom session and more for what account takeover on a client this widely deployed does to an organization’s identity perimeter. A network-reachable, no-interaction flaw in software that sits on most corporate laptops is exactly the kind of bug that turns a single unpatched machine into a foothold, particularly in VDI environments where one vulnerable image can be replicated across an entire user pool. That risk compounds the pattern CyberTech has tracked around identity enrollment and authentication flows becoming the preferred way in: attackers increasingly do not need to breach a network perimeter when a trusted client on the endpoint can be pushed to hand over the account instead.

Security teams should treat this as a patch-now item rather than a routine update cycle, especially for VDI deployments where a single unpatched golden image multiplies exposure across every session built from it, and should confirm patch compliance through endpoint management rather than relying on user-driven updates.

Source: Zoom Security Bulletin ZSB-26014