[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fDzDJoIQEkWXmyeum0yi4zh0hN0ONUS9eqMbKeWFyJ0s":3},{"article":4,"iocs":55},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":32,"category":33,"article_tags":37},"250751aa-5285-43d2-be7d-fbeb3ebdf4f8","Zoom Patches Zero-Click Code Execution Vulnerability","zoom-patches-zero-click-code-execution-vulnerability-dd0027","Impacting Zoom annotation, the bug could be exploited by a meeting participant to execute code on another participant’s machine. The post Zoom Patches Zero-Click Code Execution Vulnerability appeared first on SecurityWeek.","Zoom has released patches for four vulnerabilities, including a critical zero-click remote code execution (RCE) flaw (CVE-2026-53413) in its annotation feature. Discovered by A Security, the bug allowed a meeting participant to execute code on another participant's machine without any user interaction or visual cues. The company also addressed a denial-of-service vulnerability (CVE-2026-53414) and a use-after-free flaw (CVE-2026-53415) in the same feature, along with a path traversal vulnerability (CVE-2026-53416) in its VDI client.","Zoom patches zero-click RCE vulnerability in its annotation feature.","Zoom on Tuesday announced rolling out patches for four vulnerabilities in its products, including a severe flaw that allowed zero-click remote code execution (RCE). Impacting Zoom’s clients on all supported platforms, three of the security defects were discovered in the annotator function, which uses a proprietary protocol. The most severe of the three bugs is CVE-2026-53413, a memory corruption issue that allowed a meeting participant to execute code on another participant’s machine, says A Security, which found the bug and named it Zoomsday. The security firm exploited “the fact that every Zoom client automatically parses whatever it receives, sending a specially crafted message to corrupt the receiving client’s memory and run code on it.” An attacker could leverage the fact that the proprietary protocol used by the annotator opens a direct channel between a viewer and a sharer, thereby targeting each meeting participant individually. “The exploit enables attackers to either join or host a meeting, target any participant, and take over their machine with no required action from the victim and no visual cue indicating the compromise,” A Security explains.Advertisement. Scroll to continue reading. A missing bound check in the text annotator allowed an attacker to send crafted messages that would write attacker-supplied code past the intended buffer, leading to RCE. Additionally, A Security found CVE-2026-53414, another missing bound check in the annotator, which could be exploited to trigger a buffer overread and target any meeting participant with a denial-of-service (DoS) attack. The cybersecurity firm says it also identified CVE-2026-53415, a use-after-free flaw in the annotator function, but learned after reporting it that Zoom had already discovered it. “Because a zero-click RCE requires no user interaction, we prioritized giving customers time to receive both the client patch and the server-side mitigation before publishing. This post follows that coordinated timeline, and we are releasing it alongside CVE assignment,” A Security notes. On Tuesday, Zoom announced that Workplace versions 7.1.5 and 7.0.6, Rooms version 7.1.5, and Meeting SDK version 7.1.5 for all supported platforms contain fixes for all three vulnerabilities. Zoom also rolled out Workplace VDI Client for Windows versions 7.0.11 and 6.6.16, and Workplace VDI Plugins versions 7.0.11 and 6.6.15, for all platforms, with patches for CVE-2026-53416, a path traversal flaw leading to information disclosure. Additional information on the resolved vulnerabilities can be found on Zoom’s security bulletins page. Related: SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities Related: Microsoft, Apple Release Fresh Security Updates Related: Splunk, Zoom Patch Critical Vulnerabilities Related: Splunk, Zoom Patch Severe Vulnerabilities Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents BadMetabase Patches Vulnerability Exploited as Zero-DayCISA Urges Immediate Patching of Exploited Progress LoadMaster VulnerabilityCorporate Data Stolen in Levi Strauss CyberattackVishing Extortion Group UNC6671 Rebrands After Making MillionsMicrosoft, Apple Release Fresh Security Updates3.8 Million Impacted by Unlimited Technology Systems Data Breach Latest News The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close ItSAP Patches Critical Code Injection, Memory Corruption VulnerabilitiesUS Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’Corma Raises $60 Million for Defensive Cybersecurity AI ModelExtension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious ActivitiesHacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to RedemptionOpenAI Unveils New Cybersecurity Model GPT-5.6-CyberMozilla Issues New Firefox GPG Key Following Exposure Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Rethinking Cyber Defense for AI-Speed Attacks August 18, 2026 Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the Move1Kosmos has named Frank Cohen Chief Revenue Officer.ServiceNow has appointed Simon Mouyal as Chief Marketing Officer.James Wilkinson has been named Chief Information Security Officer for the City of Dallas.More People On The MoveExpert Insights The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It Organizations are rushing to implement AI without fully grasping where its legal protections begin and end. (Steve Durbin) Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. (Etay Maor) Timeless Compliance: Why Better Questions Beat Bigger Frameworks The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea) Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fzoom-patches-zero-click-code-execution-vulnerability\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2023\u002F06\u002FZoom-Data-Security-Privacy.jpg","2026-08-11T15:49:53+00:00","2026-08-11T16:00:24.747094+00:00",9,[18,21,23,25,27,29],{"name":19,"type":20},"Zoom annotation","product",{"name":22,"type":20},"Zoom Workplace",{"name":24,"type":20},"Zoom Rooms",{"name":26,"type":20},"Zoom Meeting SDK",{"name":28,"type":20},"Zoom VDI Client",{"name":30,"type":31},"Zoom","vendor","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":32,"icon":34,"name":35,"slug":36},null,"Vulnerabilities","vulnerabilities",[38,43,48,50],{"category":39},{"id":40,"icon":34,"name":41,"slug":42},"02371804-cf6d-4449-98de-f1a2d4d9b266","Tools","tools",{"category":44},{"id":45,"icon":34,"name":46,"slug":47},"574f766a-fb3f-487c-8d2c-0720ae75471b","Zero-day","zero-day",{"category":49},{"id":32,"icon":34,"name":35,"slug":36},{"category":51},{"id":52,"icon":34,"name":53,"slug":54},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[56,60,63,66],{"type":57,"value":58,"context":59},"cve","CVE-2026-53413","Zero-click RCE vulnerability in Zoom annotator.",{"type":57,"value":61,"context":62},"CVE-2026-53414","Denial-of-service vulnerability in Zoom annotator.",{"type":57,"value":64,"context":65},"CVE-2026-53415","Use-after-free flaw in Zoom annotator.",{"type":57,"value":67,"context":68},"CVE-2026-53416","Path traversal vulnerability in Zoom VDI client."]