Zoom Security Update – 11 March 2026

Zoom has released a security update to fix several vulnerabilities across multiple Zoom products.

The addressed vulnerabilities could allow the attacker to gain elevated privileges on the affected system.

Sample of the addressed vulnerabilities:

Zoom Workplace for Windows – External Control of File Name or Path (CVE-2026- 30903):

  • CVSS: 9.6
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Gain Privileges

The Affected Products:

  • Zoom Workplace for Windows before version 6.6.0.
  • Zoom Workplace VDI Client for Windows before versions 6.4.17, 6.5.15, and 6.6.10 in their respective branch.
  • Zoom Rooms for Windows before version 6.6.5.
  • Zoom Meeting SDK for Windows before version 6.6.11 in the 6.6.x branch.
Vulnerabilities
  • CVE-2026-30900
  • CVE-2026-30901
  • CVE-2026-30902
  • CVE-2026-30903
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Zoom Security Advisory

References