By vendor

Zoom vulnerabilities

Known CVEs affecting Zoom products, prioritized by severity, with SEC.co remediation and detection guidance.

3 published vulnerabilities

  • CVE-2026-53407HIGH 8.1

    Zoom Workplace for mobile devices contains an authorization flaw in how it handles custom URL schemes. An attacker with network access and valid Zoom credentials could craft a malicious link or request that bypasses intended security controls, allowing them to escalate their privileges within the application. The vulnerability affects Android versions before 7.0.4 and iOS versions before 7.0.3. While this requires some form of authentication to exploit, the impact allows an attacker to gain elevated access they shouldn't normally have.

  • CVE-2026-53408HIGH 8.1

    Zoom Workplace for Android and iOS contains a flaw in how it handles custom URL schemes, allowing someone with network access to bypass normal authorization checks and gain elevated privileges on the device. An unauthenticated attacker can craft a malicious link or redirect that exploits this improper authorization logic, potentially gaining access to sensitive features or data within the app without proper authentication. This affects Android versions before 7.0.4 and iOS versions before 7.0.3.

  • CVE-2026-53406HIGH 7.8

    A vulnerability in Zoom Contact Center's Remote Control feature for Windows allows authenticated users with local system access to escalate their privileges beyond their intended permissions. The issue stems from insufficient validation of data authenticity in the remote control mechanism. An attacker who already has a user account and can log into an affected system could exploit this to gain higher-level system access. This is not a critical worm-spreading vulnerability, but it does create a meaningful pathway for privilege escalation on vulnerable systems.