Zoom has released security updates to address a critical vulnerability in its Windows clients that could allow unauthenticated attackers to take over user accounts, along with three other high-severity flaws.

Reader brief
No Reader read of this story yet.
What was said2
Attributed, verbatim. Every quote is checked against the article it came from. One that does not match is not shown.
ServiceNow
2 quotes“ServiceNow is aware of a cybersecurity company's recent publication regarding exploitation activity associated with a previously disclosed security vulnerability, identified as CVE-2026-6875”
“Based on our investigation to date, we have not observed evidence that this activity is related to instances that ServiceNow hosts.”
So what4
Who is affected first and what likely follows, with a direction and a horizon. Extracted from the reports, never invented.
- Zoom Windows client users account takeover risk· immediate
- Organizations using Zoom Rooms and VDI clients privilege escalation risk· immediate
- IT administrators patch deployment urgency· days
- Zoom platform availability service disruption risk· days
Sources3
All filed from IndiaSingle originNamed United States · Apache · Lmsys · Adam Kues · Benjamin Harris · CISA · Defused · Hive · Kudankulam Nuclear Power Plant · Microsoft · Okta · QiAnXin XLab · Reliance Infra
- [1]The Hacker NewsneutralThree CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL
- [2]The Hacker Newsalarmist⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
- [3]The Hacker NewsneutralZoom Patches Critical Windows Flaw That Could Enable Account Takeover