Zoom Security Updates – 13 May 2026

Zoom has released security updates to fix several vulnerabilities across multiple Zoom products.

The addressed vulnerabilities could allow the attacker to obtain sensitive information or gain elevated privileges on the affected systems.

Sample of the addressed vulnerabilities:

Zoom Rooms for Windows – Untrusted Search Path Vulnerability (CVE-2026- 30906):

  • CVSS: 7.8
  • Attack Vector: Local
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Gain Privileges

The affected products:

  • Zoom Workplace VDI Plugin version 6.6.10.
  • Zoom Workplace for iOS before version 7.0.0.
  • Zoom Rooms for Windows before version 7.0.0.
Vulnerabilities
  • CVE-2026-30904
  • CVE-2026-30905
  • CVE-2026-30906
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Zoom Security Advisory

References