Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Zoom Communications, Inc.

First CVE: Aug 6, 2004Active for: 22 yearsTotal CVEs: 232
34.7
VTI Score
Medium

Zoom Communications maintains a widely deployed unified communications platform spanning meeting software, development kits, workplace collaboration tools, and virtual desktop infrastructure, representing one of the most prominent attack surfaces in the remote-work and conferencing landscape. Vulnerabilities affecting the vendor skew toward moderate severity outcomes, and the exposure recurs across its product portfolio through weakness classes including improper input validation, untrusted search paths, and improper cryptographic signature verification, reflecting the complexity of real-time media handling and trust-boundary enforcement. The vendor's role as a CNA and the breadth of its interconnected products mean that flaws in core meeting or SDK components can propagate across multiple downstream applications and deployment contexts. Defenders should treat Zoom's advisories as broadly applicable to conferencing infrastructure and integrate patch cycles into communications-platform maintenance schedules; current severity and exploitation activity are shown alongside this summary.

FAUCET AI Generated
232
Total CVEs
More Total CVEs than 100% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 52% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Zoom Communications, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 6, 2004
21 years ago
Most Recent CVE
Jun 12, 2026
42 days ago

Self-Reporting Analysis

Of all the CVEs published by Zoom Communications, Inc. as a CNA, 94.2% affect products that Zoom Communications, Inc. develops as a vendor.

94.2%
Self-reported: 213 (94.2%)
Third-party: 13 (5.8%)

Of all the CVEs published that affect products developed by Zoom Communications, Inc., 91.8% are self-published by Zoom Communications, Inc. as a CNA.

91.8%
Self-published: 213 (91.8%)
Other CNAs: 19 (8.2%)

Products(62 total)

Top CVEs

Signals from CVEs in this vendor scope (232 CVEs).

232 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-15049HIGH
The ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 does not properly sanitize user input when constructing a shell command, which allows remote attackers t
Dec 19, 20178.847NOYES
CVE-2017-15048HIGH
Stack-based buffer overflow in the ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 allows remote attackers to execute arbitrary code by leveraging the zoomm
Dec 19, 20178.843NOYES
CVE-2026-53407CRITICAL
Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an
Jun 12, 20269.839NONO
CVE-2025-64741CRITICAL
Improper authorization handling in Zoom Workplace for Android before version 6.5.10 may allow an unauthenticated user to conduct an escalation of privilege via network access.
Nov 13, 20259.835NONO
CVE-2026-30903CRITICAL
External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via net
Mar 11, 20269.834NONO
CVE-2021-34423CRITICAL
A buffer overflow vulnerability was discovered in Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackber
Nov 24, 20219.834NONO
CVE-2025-49457HIGH
Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access
Aug 12, 20258.833NONO
CVE-2004-0680HIGH
Zoom X3 ADSL modem has a terminal running on port 254 that can be accessed using the default HTML management password, even if the password has been changed for the HTTP interface,
Aug 6, 200410.033NONO
CVE-2026-53408HIGH
Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an
Jun 12, 20268.132NONO
CVE-2026-53406HIGH
Insufficient Verification of Data Authenticity in Remote Control for Zoom Contact Center for Windows before version 7.0.0 may allow an authenticated user to enable an escalation of
Jun 12, 20267.832NONO
View all 232 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products232 CVEs
41%
49%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local78 (33.6%)
Network147 (63.4%)
Unknown2 (0.9%)
Physical1 (0.4%)
Adjacent Network4 (1.7%)
Attack Complexity
Low221 (95.3%)
High9 (3.9%)
Unknown2 (0.9%)
User Interaction
None188 (81.0%)
Unknown2 (0.9%)
Required42 (18.1%)
Privileges Required
Low133 (57.3%)
High14 (6.0%)
None83 (35.8%)
Unknown2 (0.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (232 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
0.9% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Zoom Communications, Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Zoom Communications, Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Zoom Communications, Inc.'s Products

View all 5 CNAs →

Top CWEs