CVE-2026-53410 HIGH

CVE-2026-53410: Zoom Clients for Windows - Race Condition

Vendor Zoom Communications
Product Zoom Clients
Weakness CWE-367
Published July 16, 2026
Last update July 17, 2026

CVSS base score

7.0/10
Attack vector Local
Attack complexity High
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to escalate privileges.

Key dates

02Disclosure timeline

July 16, 2026 CVE published
July 17, 2026 Record updated