438/69 Thursday, August 13, 2026
Zoom has released a security update to fix CVE-2026-53413, a High-severity vulnerability with a CVSS score of 8.3 in the Annotation feature of Zoom clients. The vulnerability could allow an attacker who joins a meeting to execute code on other participants’ devices without requiring users to download files or click malicious links.
Reports indicate that the vulnerability is caused by insufficient bounds checking in the Annotation feature, resulting in a buffer overwrite when the Zoom client processes specially crafted data. This could lead to code execution on the system. In addition, related vulnerabilities were also identified, including CVE-2026-53414, a Medium-severity flaw that could cause other participants’ applications to crash, and CVE-2026-53415, a High-severity Use-after-free vulnerability.
CVE-2026-53413 affects Zoom Workplace on all supported platforms before versions 7.1.5 and 7.0.6, depending on the release branch; Zoom Workplace VDI Client for Windows before versions 7.0.11 and 6.6.16; Zoom Rooms on supported platforms before version 7.1.0; and Zoom Meeting SDK on supported platforms before version 7.1.0. Users and administrators should check and update Zoom products to the latest versions as soon as possible to reduce the risk of exploitation through this vulnerability.
