Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-8037 · Progress LoadMaster Command Injection Vulnerability · Added 2026-08-07 · Due 2026-08-10CISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-8037 · Progress LoadMaster Command Injection Vulnerability · Added 2026-08-07 · Due 2026-08-10CISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08

Vendors · zoom

zoom

· 11 Critical

Total CVEs

226

Critical

11

Products

61

Search All CVEs →

226

Products (61)

rooms106 CVEsmeeting software development kit83 CVEsworkplace desktop73 CVEszoom63 CVEsworkplace virtual desktop infrastructure56 CVEsrooms controller44 CVEsworkplace39 CVEsmeetings37 CVEsvirtual desktop infrastructure25 CVEsvideo software development kit23 CVEsvdi windows meeting clients9 CVEszoom on-premise meeting connector mmr9 CVEsmeeting connector6 CVEszoom on-premise meeting connector controller5 CVEszoom on-premise virtual room connector load balancer4 CVEsrooms for conference rooms4 CVEszoom on-premise virtual room connector4 CVEszoom on-premise recording connector4 CVEszoom plugin for microsoft outlook3 CVEsvirtual room connector2 CVEsvirtual room connector load balancer2 CVEswindows video sdk2 CVEswindows meeting sdk2 CVEsmeeting sdk2 CVEsmeetings for blackberry2 CVEsmeetings for chrome os2 CVEsmeetings for intune2 CVEszoom client for meetings2 CVEscontrollers for zoom rooms2 CVEsandroid meeting sdk2 CVEshybrid mmr2 CVEshybrid zproxy2 CVEsiphone os meeting sdk2 CVEsiphone os video sdk2 CVEsandroid video sdk2 CVEsrecording connector2 CVEsmacos meeting sdk2 CVEsmacos video sdk2 CVEsvdi azure virtual desktop2 CVEsvdi citrix2 CVEsvdi vmware2 CVEszoom software development kit1 CVEschat1 CVEscleanzoom1 CVEsit installer1 CVEsmodel 5560 x3 ethernet adsl modem1 CVEson-premise meeting connector multimedia router1 CVEspoly ccx 6001 CVEspoly ccx 600 firmware1 CVEspoly ccx 7001 CVEspoly ccx 700 firmware1 CVEsscreen sharing1 CVEssharing service1 CVEsvdi windows meeting client1 CVEsyealink mp541 CVEsyealink mp54 firmware1 CVEsyealink mp561 CVEsyealink mp56 firmware1 CVEsyealink vp591 CVEsyealink vp59 firmware1 CVEszoom cloud meetings1 CVEs

Recent Vulnerabilities

View all 226
CVE-2026-30903CRITICAL 9.6

External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via network access.

CVE-2026-30902HIGH 7.8

Improper Privilege Management in certain Zoom Clients for Windows may allow an authenticated user to conduct an escalation of privilege via local access.

CVE-2026-30901HIGH 7.0

Improper Input Validation in Zoom Rooms for Windows before 6.6.5 in Kiosk Mode may allow an authenticated user to conduct an escalation of privilege via local access.

CVE-2026-30900HIGH 7.8

Improper Check of minimum version in update functionality of certain Zoom Clients for Windows may allow an authenticated user to conduct an escalation of privilege via local access.

CVE-2025-67461MEDIUM 5.0

External control of file name or path in Zoom Rooms for macOS before version 6.6.0 may allow an authenticated user to conduct a disclosure of information via local access.

CVE-2025-67460HIGH 7.8

Protection Mechanism Failure of Software Downgrade in Zoom Rooms for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via local access.

CVE-2025-62484HIGH 8.1

Inefficient regular expression complexity in certain Zoom Workplace Clients before version 6.5.10 may allow an unauthenticated user to conduct an escalation of privilege via network access.

CVE-2025-64741HIGH 8.1

Improper authorization handling in Zoom Workplace for Android before version 6.5.10 may allow an unauthenticated user to conduct an escalation of privilege via network access.

CVE-2025-64740HIGH 7.5

Improper verification of cryptographic signature in the installer for Zoom Workplace VDI Client for Windows may allow an authenticated user to conduct an escalation of privilege via local access.

CVE-2025-64739MEDIUM 4.3

External control of file name or path in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via network access.

CVE-2025-64738MEDIUM 5.0

External control of file name or path in Zoom Workplace for macOS before version 6.5.10 may allow an authenticated user to conduct a disclosure of information via local access.

CVE-2025-62483MEDIUM 5.3

Improper removal of sensitive information in certain Zoom Clients before version 6.5.10 may allow an unauthenticated user to conduct a disclosure of information via network access.

CVE-2025-62482MEDIUM 4.3

Cross-site scripting in Zoom Workplace for Windows before version 6.5.10 may allow an unauthenticated user to impact integrity via network access.

CVE-2025-30669MEDIUM 4.8

Improper certificate validation in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via adjacent access.

CVE-2025-30662MEDIUM 6.6

Symlink following in the installer for the Zoom Workplace VDI Plugin macOS Universal installer before version 6.3.14, 6.4.14, and 6.5.10 in their respective tracks may allow an authenticated user to conduct a disclosure of information via network access.

CVE-2025-58133MEDIUM 5.3

Authentication bypass in some Zoom Rooms Clients before version 6.5.1 may allow an unauthenticated user to conduct a disclosure of information via network access.

CVE-2025-58132MEDIUM 4.1

Command injection in some Zoom Clients for Windows may allow an authenticated user to conduct a disclosure of information via network access.

CVE-2025-58135MEDIUM 5.3

Improper action enforcement in certain Zoom Workplace Clients for Windows may allow an unauthenticated user to conduct a disclosure of information via network access.

CVE-2025-58134MEDIUM 4.3

Incorrect authorization in certain Zoom Workplace Clients for Windows may allow an authenticated user to conduct an impact to integrity via network access.

CVE-2025-49461MEDIUM 4.3

Cross-site scripting in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denial of service via network access.

CVE-2025-49460MEDIUM 4.3

Uncontrolled resource consumption in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denial of service via network access.

CVE-2025-49458MEDIUM 6.5

Buffer overflow in certain Zoom Workplace Clients may allow an authenticated user to conduct a denial of service via network access.

CVE-2025-49457CRITICAL 9.6

Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access

CVE-2025-49456MEDIUM 6.2

Race condition in the installer for certain Zoom Clients for Windows may allow an unauthenticated user to impact application integrity via local access.

CVE-2025-49464MEDIUM 6.5

Classic buffer overflow in certain Zoom Clients for Windows may allow an authorised user to conduct a denial of service via network access.