The National Information Technology Development Agency (NITDA) has issued a fresh cybersecurity alert warning individuals, businesses, and government institutions about multiple critical vulnerabilities discovered in several Zoom products, raising concerns over potential system compromise and unauthorized access.
In an advisory released through its Computer Emergency Readiness and Response Team (CERRT.NG), NITDA disclosed that the security flaws affect a range of Zoom services, including Zoom Workplace, Zoom Clients, Zoom Rooms, and Virtual Desktop Infrastructure (VDI) components, particularly in Windows-based environments.
According to the agency, the vulnerabilities are tracked as CVE-2026-30900, CVE-2026-30901, CVE-2026-30902, CVE-2026-30903, CVE-2025-49457, and CVE-2025-58132.
NITDA identified CVE-2026-30903 as one of the most severe vulnerabilities, noting that it affects the Zoom Workplace Mail feature and stems from improper handling of file names and file paths.
“The vulnerability is associated with improper handling of file names and file paths, potentially exposing targeted systems to malicious activity,” the agency stated in the advisory.
The agency warned that successful exploitation of the flaws could hand cybercriminals significant control over affected systems.
“Successful exploitation of these vulnerabilities could allow threat actors to escalate privileges, execute unauthorized commands, bypass security controls, gain unauthorized access to affected systems, or disrupt normal application and system operations,” NITDA said.
It added that in extreme cases, attackers could obtain elevated system-level privileges, increasing the risk of widespread compromise of enterprise communication environments.
“In severe cases, attackers may achieve elevated system-level access, increasing the risk of system compromise, operational disruption, and unauthorized manipulation of enterprise communication environments,” the advisory noted.
To mitigate the risks, NITDA urged organizations and users to immediately update all Zoom products to the latest supported versions and apply the security patches contained in Zoom Security Bulletins ZSB-26001 to ZSB-26005.
The agency also advised organizations to remove outdated or unsupported Zoom installations, activate automatic updates wherever possible, and educate users on the dangers of suspicious meeting links, attachments, and content received through Zoom Workplace Mail.
The warning comes amid growing global concerns over cyber threats targeting communication and collaboration platforms widely used by businesses, government agencies, and educational institutions.
NITDA emphasized that prompt action is necessary to prevent exploitation and protect sensitive digital infrastructure from potential attacks.