A critical account takeover vulnerability affecting widely deployed collaboration software deserves immediate attention, particularly because exploitation may require no authentication and can occur remotely over the network.

Organizations should urgently identify affected Zoom Workplace, VDI Client, and Meeting SDK installations on Windows and upgrade them to the fixed versions. Enterprises should not rely only on users updating manually; centralized software inventory, enforced patch deployment, and verification of installed versions are essential.

Although there is currently no reported exploitation, the severity of the vulnerability and the potential impact of compromised accounts make delayed patching an unnecessary risk.


Zoom is warning of a critical vulnerability in its desktop client and software development kit for Windows that could be exploited by an unauthenticated party to hijack accounts. [...]

Source: Zoom warns of critical account takeover vulnerability via Bleeping Computer — published 15 Jul 2026.