Zoom Communications maintains a widely deployed unified communications platform spanning meeting software, development kits, workplace collaboration tools, and virtual desktop infrastructure, representing one of the most prominent attack surfaces in the remote-work and conferencing landscape. Vulnerabilities affecting the vendor skew toward moderate severity outcomes, and the exposure recurs across its product portfolio through weakness classes including improper input validation, untrusted search paths, and improper cryptographic signature verification, reflecting the complexity of real-time media handling and trust-boundary enforcement. The vendor's role as a CNA and the breadth of its interconnected products mean that flaws in core meeting or SDK components can propagate across multiple downstream applications and deployment contexts. Defenders should treat Zoom's advisories as broadly applicable to conferencing infrastructure and integrate patch cycles into communications-platform maintenance schedules; current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zoom Communications, Inc. over time
Of all the CVEs published by Zoom Communications, Inc. as a CNA, 94.2% affect products that Zoom Communications, Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Zoom Communications, Inc., 91.8% are self-published by Zoom Communications, Inc. as a CNA.
Signals from CVEs in this vendor scope (232 CVEs).
232 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-15049HIGH The ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 does not properly sanitize user input when constructing a shell command, which allows remote attackers t | Dec 19, 2017 | 8.8 | 47 | NO | YES |
CVE-2017-15048HIGH Stack-based buffer overflow in the ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 allows remote attackers to execute arbitrary code by leveraging the zoomm | Dec 19, 2017 | 8.8 | 43 | NO | YES |
CVE-2026-53407CRITICAL Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an | Jun 12, 2026 | 9.8 | 39 | NO | NO |
CVE-2025-64741CRITICAL Improper authorization handling in Zoom Workplace for Android before version 6.5.10 may allow an unauthenticated user to conduct an escalation of privilege via network access. | Nov 13, 2025 | 9.8 | 35 | NO | NO |
CVE-2026-30903CRITICAL External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via net | Mar 11, 2026 | 9.8 | 34 | NO | NO |
CVE-2021-34423CRITICAL A buffer overflow vulnerability was discovered in Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackber | Nov 24, 2021 | 9.8 | 34 | NO | NO |
CVE-2025-49457HIGH Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access | Aug 12, 2025 | 8.8 | 33 | NO | NO |
CVE-2004-0680HIGH Zoom X3 ADSL modem has a terminal running on port 254 that can be accessed using the default HTML management password, even if the password has been changed for the HTTP interface, | Aug 6, 2004 | 10.0 | 33 | NO | NO |
CVE-2026-53408HIGH Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an | Jun 12, 2026 | 8.1 | 32 | NO | NO |
CVE-2026-53406HIGH Insufficient Verification of Data Authenticity in Remote Control for Zoom Contact Center for Windows before version 7.0.0 may allow an authenticated user to enable an escalation of | Jun 12, 2026 | 7.8 | 32 | NO | NO |
Signals from CVEs in this vendor scope (232 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zoom Communications, Inc..
Media articles that mention a CVE ID that affects a product developed by Zoom Communications, Inc. — matched by CVE ID, not by vendor name.