CVE-2026-30903: Zoom Workplace Desktop

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via network access.

Affected products

  • Zoom Workplace Desktop: before 6.6.0 (fixed in 6.6.0)
  • Zoom Workplace Virtual Desktop Infrastructure: from 6.4.0, before 6.4.17 (fixed in 6.4.17); from 6.5.0, before 6.5.15 (fixed in 6.5.15); from 6.6.0, before 6.6.10 (fixed in 6.6.10)

Published 2026-03-11. Last modified 2026-06-17.