Zoom has patched a critical security flaw, tracked as CVE-2026-53412, in Zoom Workplace for Windows. It carries a CVSS score of 9.8, which is about as high as these ratings go, and it can lead to full account takeover.
The short version: if you run Zoom on Windows, open it, check for updates, and install the latest version tonight. Do not leave it for the weekend. Account-takeover bugs are exactly the kind of thing that gets weaponised quickly once a patch is public and attackers can reverse-engineer what changed.
If you manage Zoom for a team, push the update through your device management now and confirm clients have actually restarted. A patched installer sitting on disk does nothing until the app relaunches.
Why it matters: a 9.8 in a tool this widely used is a fat target. The fix is free and takes two minutes. The cost of skipping it is someone else reading your calls and messages.
Related: Microsoft's July patch haul and SharePoint zero-days under attack.