CVE-2026-30903Disclosure(zoom / workplace_desktop)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch zoom workplace_desktop systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via network access.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-73CWE-610

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • workplace_desktop
  • workplace_virtual_desktop_infrastructure

Threat summary

  • Patch or workaround signal is available
  • 15 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 13 signals
  • Disclosure: 7 classified signals
  • General: 3 classified signals
  • Peaked 4d ago at 7 mentions (2026-03-11); latest day: 1
  • 15 total mentions across 6 days

Affected systems

Vendors
Products
workplace_desktopworkplace_virtual_desktop_infrastructure

Deep dive

Activity timeline15 mentions / 6d
02457Mentions · 2026-03-10: 2Mentions · 2026-03-11: 7Mentions · 2026-03-12: 2Mentions · 2026-03-13: 1Mentions · 2026-03-15: 2Mentions · 2026-06-16: 1Patch / Workaround · 2026-03-10: 1Patch / Workaround · 2026-03-11: 2Patch / Workaround · 2026-03-12: 1Technical Details · 2026-03-10: 2Technical Details · 2026-03-11: 7Technical Details · 2026-03-12: 1Technical Details · 2026-03-13: 1Technical Details · 2026-03-15: 203-1003-1103-1203-1303-1506-16
Signal classification3 categories
Disclosure
746.7%
Patch
533.3%
General
320.0%
Referenced assets14 URLs
Classification over time
DateTotalLabels
2026-03-102
Disclosure1Patch1
2026-03-117
Disclosure4General1Patch2
2026-03-122
General1Patch1
2026-03-131
Patch1
2026-03-152
Disclosure2
2026-06-161
General1
Full discourse15 posts
  • Gray Hats@the_yellow_fall
    Patch

    Zoom patches a critical 9.6 CVSS flaw (CVE-2026-30903) allowing unauthenticated remote privilege escalation on Windows. Update your clients immediately. #Zoom #CVE202630903 #CyberSecurity #InfoSec #PatchAlert #Vulnerability #WindowsSecurity https://securityonline.info/unauthenticated-takeover-critical-9-6-cvss-zoom-flaw-exposes-windows-users-to-remote-privilege-escalation/ https://t.co/7GsZiSOIlh

    Post summary

    Zoom has released a patch for CVE‑2026‑30903, a high‑severity flaw that allowed unauthenticated remote privilege escalation on Windows, and urges users to update immediately.

    01301651.3K
    10.6K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    Zoom Workplace for Windowsで重大(Critical)な権限昇格の脆弱性が修正。CVE-2026-30903 (ZSB-26005)は遠隔から無認証での権限昇格。メール機能における脆弱性で悪用にはユーザ関与要。その他脆弱性も複数。 https://cybersecuritynews.com/zoom-workplace-for-windows-vulnerabilities/

    Post summary

    Zoom Workplace for Windows had a critical privilege‑elevation vulnerability (CVE‑2026‑30903) that has been patched; the linked article discusses the update but does not mention PoCs, exploits, or active attacks.

    030211.1K
    7.3K followersView on X
  • Marcin Nolte 🇵🇱🇩🇪🇺🇸@NolteIT
    Patch

    CVE-2026-30903 in Zoom: CVSS 9.6, kritisch. Angreifer aus dem Netz, ohne Authentifizierung, Rechteausweitung über die Mail-Funktion in Zoom Workplace für Windows. Dazu drei weitere Lücken, alle als „hoch“ eingestuft (CVSS 7.0–7.8). Updates sind draußen: Zoom Workplace 6.6.11. Zoom läuft in fast jeder Unternehmensumgebung. Wer das heute nicht patcht, erklärt seinem Angreifer, wo die Tür offen steht. https://www.heise.de/news/Zoom-Videokonferenzsoftware-ermoeglicht-Angreifern-Rechteausweitung-11208902.html #Zoom #Cybersecurity

    Post summary

    The article announces a critical Zoom Workplace vulnerability (CVE‑2026‑30903) that permits unauthenticated privilege escalation, recommends installing version 6.6.11, and notes several other high‑severity flaws.

    00020124
    73 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: #Zoom has released security updates for 4 vulnerabilities in its Windows ecosystem, including a Critical flaw (CVE-2026-30903, CVSSv3 9.6) which allows remote, unauthenticated privilege escalation. Time to #Patch #Patch #Patch

    Post summary

    Zoom has issued patches for four Windows vulnerabilities, including a critical remote privilege escalation flaw (CVE-2026-30903). Users should apply the updates promptly.

    01001258
    7.2K followersView on X
  • Directoratul Național de Securitate Cibernetică@DNSC_RO
    Disclosure

    🚨 ALERTĂ: Vulnerabilitate critică în Zoom Workplace 🔎 Experții în securitate cibernetică au identificat o vulnerabilitate critică, CVE-2026-30903, în modulul de Mail al aplicației Zoom Workplace pentru Windows, având un scor CVSS v3.1 de 9.6. 👉 https://www.dnsc.ro/citeste/alerta-vulnerabilitate-critica-in-zoom-workplace #DNSC https://t.co/BKhB5SBakG

    Post summary

    The tweet announces the discovery of CVE-2026-30903, a critical vulnerability in Zoom Workplace’s mail module for Windows, noting its high CVSS v3.1 score of 9.6.

    02000176
    4.7K followersView on X
  • stephen Adeoye@punkdry
    General

    A recent http://CERT.NG advisory on multiple critical Zoom vulnerabilities, including CVE-2026-30903, highlights an important cybersecurity reality: No organization is immune to vulnerabilities. #Cyber_woLife #zoom https://t.co/3wPcwgrS93

    Post summary

    The tweet references a CERT advisory that lists multiple critical Zoom vulnerabilities, including CVE-2026-30903, but offers no detailed technical, exploit, or patch information beyond the advisory link.

    1000085
    8 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-20127 2 - CVE-2026-30903 3 - CVE-2026-27944 4 - CVE-2026-28292 5 - CVE-2026-26117 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post merely lists the top 5 trending CVEs without providing additional context or technical information.

    00010163
    1.7K followersView on X
  • まっちゃだいふく@ripjyr
    Disclosure

    Zoomに、Criticalの脆弱性情報 ZSB-26005 が公開されました。 「CVE-2026-30903 : Zoom Workplace for Windows - External Control of File Name or Path」 CVSSv3: 9.6 → https://www.zoom.com/en/trust/security-bulletin/ZSB-26005/

    Post summary

    Zoom has publicly disclosed a critical vulnerability (CVE-2026-30903) with CVSS 9.6; the text contains only the announcement and basic details, with no mention of exploitation or patches.

    01000430
    8.6K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-30903 External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of pri… https://www.cve.org/CVERecord?id=CVE-2026-30903 ----- Traducción: Control externo de… http://infoflow.cloud`

    Post summary

    This is a straightforward CVE announcement for CVE-2026-30903, identifying an external file name/path control flaw in Zoom Workplace that could enable unauthenticated privilege escalation, with no PoC, exploit, or patch referenced.

    0000039
    57 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-30903 External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of pri… https://www.cve.org/CVERecord?id=CVE-2026-30903

    Post summary

    The snippet simply links to a CVE record for CVE-2026-30903, noting a potential privilege escalation via file name/path control in Zoom Workplace, with no evidence of exploitation, PoC, or patch information provided.

    00000378
    56.7K followersView on X
  • Eyal Estrin ☁️@eyalestrin
    Patch

    Zoom Workplace for Windows - External Control of File Name or Path (CVE-2026-30903) http://dlvr.it/TRSrj6 #patchmanagement

    Post summary

    The message references CVE-2026-30903 and hints at patch‑management but provides no PoC, exploit, or active exploitation details, merely noting a vulnerability type.

    0000039
    2.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-30903 - Zoom Workplace for Windows Path Traversal Vulnerability Intel Report: https://ift.tt/DPZitLN

    Post summary

    The tweet is a brief threat alert referencing CVE-2026-30903 (Zoom Workplace path traversal) with a link to an intel report.

    0000045
    343 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-30903: CRITICAL] Zoom Workplace for Windows version before 6.6.0 is vulnerable to external control of file name or path in the Mail feature, risking escalation of privilege for unauthorized users.#cve,CVE-2026-30903,#cybersecurity https://cvefind.com/CVE-2026-30903

    Post summary

    A critical Zoom Workplace vulnerability (CVE‑2026‑30903) affecting versions before 6.6.0 is disclosed, involving external control of file names or paths in the Mail feature, leading to privilege escalation; no exploit or patch details are mentioned.

    0000034
    601 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-30903 - Critical External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via network ac... https://www.thehackerwire.com/vulnerability/CVE-2026-30903/ https://t.co/TnLRY93wAx

    Post summary

    The tweet announces a critical CVE-2026-30903 affecting Zoom Workplace, describing an unauthenticated privilege escalation vulnerability via external file names or paths in the Mail feature.

    0000044
    134 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-30903: Zoom Communications (CVSS: 9.6)... Path traversal in Zoom's mail feature hits CVSS 9.6 - unauthenticated network attackers can escalate privileges by cont... https://zerodaysignal.com/vulnerability/CVE-2026-30903 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces a high‑severity path traversal flaw (CVSS 9.6) in Zoom’s mail feature that could allow unauthenticated network attackers to gain privileges, but it provides no PoC, exploit code, or patch information.

    0000055
    143 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appzoomworkplace_desktop-windows-
Appzoomworkplace_virtual_desktop_infrastructure-windows-

Explore more