Zoom — the video app sitting on just about every business computer in America — just patched one of the most serious flaws it has ever disclosed: a 9.8-out-of-10 vulnerability in its Windows apps that could let a complete stranger, with no password and no login, take over a user’s account across the network. The good news: Zoom’s own security team found it, a fix is already available, and there is no sign anyone has exploited it in the wild. The catch, and the entire reason we are writing this: the fix only protects the computers that actually get it.
The essentials, at a glance
| What happened | Zoom disclosed and patched a critical flaw rated 9.8 out of 10 in its Windows software |
| What it could allow | An attacker with no password and no account access to take over a user’s Zoom account remotely |
| Who is affected | The Zoom desktop app for Windows before version 7.0.0, plus Zoom’s virtual-desktop versions and apps built on Zoom’s meeting toolkit |
| What an account holds | More than meetings: archived chat conversations, contacts, cloud recordings — and often sign-in connections that reach further into a business |
| Current status | Patched. No known attacks so far. Update via the app or zoom.us/download |
| Also fixed | Three additional high-severity flaws in the same batch of updates |
Why “no known attacks” is not the same as “no rush”
Here is how this always plays out, and why the calm headline is deceptive. The moment a fix is published, the race begins. Criminals study new patches specifically to work out what got fixed, because every announcement is also a map: it tells them a serious door exists, and that every computer that has not updated yet still has it wide open. The businesses that get hurt by flaws like this are rarely the ones attacked before the patch existed — they are the ones attacked weeks or months after, still running the old version because nobody ever got around to updating.
The way to think about every patch: a published fix starts a clock. On one side, you updating. On the other, criminals reverse-engineering the fix to find the hole it closed. Whichever side finishes first wins that machine. “We’ll update eventually” is choosing to lose the race on purpose.
The uncomfortable question for every small business
So the advice this week is simple: update Zoom on every Windows machine. But pause on the harder question underneath it — who, in your business, actually makes sure that happens? Not “who will probably click the update button eventually,” but who owns the job of confirming that every computer — the front desk, the laptop that mostly lives in a truck, the machine the part-timer uses on Saturdays — is actually running the fixed version? In most small businesses, the honest answer is nobody:
- Updates are left to each user — and busy people click “remind me later” for months, through no fault of their own.
- Nobody has the list — there is no inventory of which machines run what, so “are we all updated?” is unanswerable.
- Zoom is one app of dozens — the same race is running, right now, for the browser, the PDF reader, the accounting software, and the operating system on every machine you own.
This week’s homework: update Zoom on every Windows computer in your business — open the app and check for updates, or grab the current version from zoom.us/download. Don’t postpone the restart. And if a tool you use has Zoom meetings built into it, that vendor needs to ship an update too — worth a quick ask.
Patching is a job, not an event
This Zoom flaw will be forgotten in a month. But next month there will be another one — different app, same race — and the month after that, forever. Keeping every machine current is not a task you do once; it is a standing job, and in businesses without an IT department, it is a job that simply has no owner. That is exactly the gap our managed IT service closes: we keep an inventory of every machine, keep the software on them current, and win the patch race on your behalf, every month, so announcements like this one become a non-event for your business instead of a fire drill. You run the business. We’ll mind the clock.
Sources: Zoom security bulletin; The Hacker News; BleepingComputer; Security Affairs, July 2026.













