← All vendors
Vendor
Zoom
Vulnerabilities across the Zoom stack: Workplace (formerly Zoom Client), Windows and macOS VDI Clients, Meeting SDK, Rooms, and the browser plug-ins. Zoom Product Security (PSIRT) advisories, in-the-wild reports, and the desktop-client bugs that turn every enterprise's collaboration surface into an attack surface.
Articles

zoom
Zero-Click RCE in Zoom Annotation — Patch Now
A flaw in Zoom's annotation tool let any meeting participant execute code on another attendee's machine — zero clicks required. Update Zoom clients now.
read →

zoom
Zoom PSIRT: patch Workplace 7.0.0, unauth takeover 9.8
Zoom pushed a critical unauth account-takeover advisory (ZSB-26014, CVSS 9.8) for the Windows Workplace client and VDI Client — patch to 7.0.0 or the branch build.
read →