.
Nigeria’s National Information Technology Development Agency (NITDA) has warned users of Zoom about a critical security vulnerability that could allow attackers to take control of affected accounts without the need for valid login credentials.
The warning comes amid growing cybersecurity concerns around widely used digital communication platforms, with the agency urging users and organisations to take security updates seriously.
Critical Vulnerability Detected
The vulnerability, identified as CVE-2026-53412, affects Zoom Workplace for Windows and the Zoom VDI Client for Windows.
Security researchers and cybersecurity advisories have rated the flaw 9.8 out of 10 on the CVSS severity scale, placing it in the critical category.
According to Zoom’s security advisory, the vulnerability is linked to improper input validation and could enable an unauthenticated attacker to carry out an account takeover through network access.
Users Could Be Targeted Without Credentials
One of the most concerning aspects of the vulnerability is that an attacker does not necessarily need the victim’s password or other authentication credentials to exploit the flaw.
This makes outdated versions of the affected software a potential security risk for individuals, businesses and organisations that rely on Zoom for meetings, remote collaboration and other communications.
NITDA’s warning therefore underscores the importance of keeping software updated, particularly when vendors release security patches addressing high-severity vulnerabilities.
Zoom Has Released Security Updates
Zoom has already issued updates addressing the vulnerability.
The flaw affects versions of Zoom Workplace for Windows released before version 7.0.0, while affected versions of the Zoom VDI Client for Windows vary by supported branch. Zoom also disclosed additional security vulnerabilities in the same security update, including flaws involving privilege escalation.
Users running affected versions are therefore advised to move to the applicable updated releases rather than continuing to operate older software.
Wider Cybersecurity Concerns
The alert comes at a time when cybersecurity threats are becoming increasingly sophisticated and capable of targeting widely used business applications.
Recent research has also highlighted separate vulnerabilities in Zoom’s collaboration features that could potentially allow a malicious meeting participant to compromise another participant’s device. Zoom has since patched those issues as well.
The developments reinforce the importance of maintaining updated applications across devices, particularly where platforms are used to handle business communications and sensitive information.
Organisations Urged to Take Software Security Seriously
For businesses and institutions, the Zoom vulnerability is a reminder that cybersecurity risks can emerge even in commonly used productivity tools.
Keeping operating systems and applications patched, monitoring security advisories and ensuring that employees use supported software versions remain important elements of an organisation’s broader security posture.
As Nigeria continues to expand its digital economy and remote collaboration becomes more common, security agencies such as NITDA are expected to play an increasingly important role in alerting users to emerging threats.
For Zoom users, the immediate priority is straightforward: ensure affected applications are updated to patched versions and avoid relying on outdated software that may expose accounts or systems to known vulnerabilities.















