17 Total CVEs
17 AI Analyzed
0 CISA KEV
4 Critical

Profile

0% ended up actively exploited 0 of 17 added to CISA KEV
24% rated critical (CVSS 9.0+) 4 critical, 13 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

14 CVEs in the last 12 months

Products

  • Workplace2
  • Clients for2
  • Zoom Workplace for Windows1
  • Zoom Workplace VDI Plugin1
  • Zoom Rooms1
  • Contact Center1
  • Workplace for1

7 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-17 of 17 CVEs
CVE-2026-53412
Analyzed
9.8
Zoom Communications Zoom Workplace for Windows

Zoom Workplace for Windows is vulnerable to an improper input validation flaw that may enable account takeover by an unauthenticated attacker.

2026-07-17
CVE-2026-53411
Analyzed
7.8
Zoom Communications Zoom Workplace VDI Plugin

A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow...

2026-07-18
CVE-2026-53409
Analyzed
7.8
Zoom Communications Zoom Rooms

Improper Privilege Management in Zoom Rooms for Windows before version 7

2026-07-18
CVE-2026-53408
Analyzed
8.1
Zoom Communications Workplace

Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7

2026-06-14
CVE-2026-53407
Analyzed
8.1
Zoom Communications Workplace

Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7

2026-06-14
CVE-2026-53406
Analyzed
7.8
Zoom Communications Contact Center

Insufficient Verification of Data Authenticity in Remote Control for Zoom Contact Center for Windows before version 7

2026-06-14
CVE-2026-30903
Analyzed
9.6
Zoom Communications Workplace for

A path traversal vulnerability in the Mail feature of Zoom Workplace for Windows allows unauthenticated users to conduct an escalation of privilege vi...

2026-03-12
CVE-2026-30902
Analyzed
7.8
Zoom Communications Clients for

Improper Privilege Management in certain Zoom Clients for Windows may allow an authenticated user to conduct an escalation of privilege via local acce...

2026-03-13
CVE-2026-30900
Analyzed
7.8
Zoom Communications Clients for

Improper Check of minimum version in update functionality of certain Zoom Clients for Windows may allow an authenticated user to conduct an escalation...

2026-03-13
CVE-2026-22844
Analyzed
9.9
Zoom Communications Multiple Products

A Command Injection vulnerability in Zoom Node Multimedia Routers (MMRs) before version 5.2.1716.0 may allow a meeting participant to conduct remote c...

2026-01-21
CVE-2025-67460
Analyzed
7.8
Zoom Communications Multiple Products

Protection Mechanism Failure of Software Downgrade in Zoom Rooms for Windows before 6

2025-12-11
CVE-2025-64741
Analyzed
8.1
Zoom Communications Multiple Products

Improper authorization handling in Zoom Workplace for Android before version 6

2025-11-14
CVE-2025-64740
Analyzed
7.5
Zoom Communications Multiple Products

Improper verification of cryptographic signature in the installer for Zoom Workplace VDI Client for Windows may allow an authenticated user to conduct...

2025-11-14
CVE-2025-62484
Analyzed
8.1
Zoom Communications Multiple Products

Inefficient regular expression complexity in certain Zoom Workplace Clients before version 6

2025-11-14
CVE-2025-49459
Analyzed
7.8
Zoom Communications Multiple Products

Missing authorization in the installer for Zoom Workplace for Windows on ARM before version 6

2025-09-09
CVE-2025-49457
Analyzed
9.6
Zoom Communications Multiple Products

Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access

2025-08-12
CVE-2025-46788
Analyzed
7.4
Zoom Communications Multiple Products

Improper certificate validation in Zoom Workplace for Linux before version 6

2025-07-11