Zoom has released patches for four significant security vulnerabilities on Tuesday, addressing a critical zero-click remote code execution (RCE) flaw among others. These vulnerabilities posed risks across all supported platforms utilizing Zoom’s services.
Details of the Vulnerabilities
The vulnerabilities were predominantly found within the annotator function of Zoom, which operates using a proprietary protocol. The most severe issue identified was a memory corruption bug, tagged as CVE-2026-53413. This flaw permitted a meeting participant to execute unauthorized code on another participant’s device, a threat discovered and named ‘Zoomsday’ by the cybersecurity firm, A Security.
The firm revealed that the exploit involved sending crafted messages that Zoom clients automatically process, thereby corrupting the recipient’s memory to execute arbitrary code. The exploit takes advantage of the direct communication channel established by the annotator between a viewer and a sharer.
Exploits and Threat Mitigation
Attackers could leverage this exploit to join or host a meeting, targeting any participant without needing user interaction or visual indicators of the breach. Another flaw, CVE-2026-53414, involved a missing bound check, allowing attackers to initiate a buffer overread, potentially leading to a denial-of-service (DoS) attack.
A Security also uncovered CVE-2026-53415, a use-after-free vulnerability within the annotator, although Zoom had already identified this issue. Priority was given to allow customers time to apply the necessary patches and server-side mitigations before publicly disclosing these threats.
Zoom’s Response and Future Measures
In response, Zoom has updated Workplace versions 7.1.5 and 7.0.6, Rooms version 7.1.5, and Meeting SDK version 7.1.5 across all supported platforms to address these vulnerabilities. Additionally, Workplace VDI Client for Windows versions 7.0.11 and 6.6.16, along with Workplace VDI Plugins versions 7.0.11 and 6.6.15, were released to fix CVE-2026-53416, a path traversal issue that exposed sensitive information.
For more detailed information about these resolved vulnerabilities, users are encouraged to consult Zoom’s security bulletins page. Staying informed and promptly updating software are crucial steps in safeguarding against potential cyber threats.
