Nigeria’s National Information Technology Development Agency (NITDA) has warned Zoom users about a critical security vulnerability that could allow attackers to take over user accounts without valid login credentials.

The warning was issued by the NITDA Computer Emergency Readiness and Response Team (NITDA-CERRT) over a vulnerability identified as CVE-2026-53412. 

According to NITDA, the flaw affects Zoom Workplace for Windows and the Zoom Workplace VDI Client for Windows. If successfully exploited, attackers could gain unauthorised access to affected Zoom accounts and potentially access confidential meetings, chat conversations, recordings, and shared files. 

The vulnerability stems from improper input validation in the affected Zoom software. Security researchers have rated the flaw 9.8 out of 10 on the CVSS scale, placing it in the critical severity category. 

The risk is significant for organisations that use Zoom to conduct business meetings or exchange sensitive information, as a compromised account could provide attackers with access to corporate communications and files.

Zoom has already released security updates addressing the vulnerability. The company’s security bulletin lists CVE-2026-53412 as a critical issue affecting Zoom Workplace for Windows, with the vulnerability disclosed in July. 

NITDA is urging users and organisations running affected versions of Zoom to update their software immediately and ensure that security patches are applied across devices.

The warning comes as cybersecurity threats targeting widely used collaboration and communication platforms continue to increase. Zoom’s security bulletins show that the company has addressed several other vulnerabilities in its Windows clients and related products this year, including flaws capable of privilege escalation and other forms of unauthorised access. 

For Nigerian businesses and institutions that rely heavily on digital collaboration, the incident highlights the importance of timely software updates and effective patch-management practices.

NITDA’s latest alert reinforces the need for users not to treat software updates as optional, particularly where applications have access to sensitive conversations, corporate files, and business accounts.

Get Newsletter Updates

Enjoying our column?

Subscribe to our specialised **Tech Pulse** feed to receive fresh reports and analyses directly in your inbox.

Add as a preferred source on Google Follow on Google News

Folake Balogun is a technology journalist covering Africa’s digital economy, with a focus on startups, fintechs, venture capital, artificial intelligence, and emerging technologies. Her work explores the intersection of technology, business, and society, highlighting how innovation is reshaping industries and everyday life across Africa and global markets. She translates complex trends into insightful and impactful stories for a wider audience.