RESEARCH has uncovered three critical vulnerabilities in Zoom, dubbed "Zoomsday," that could allow one participant to attack another during meetings via malicious data. These flaws, tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415, impact annotation features across multiple Zoom platforms, potentially leading to crashes, data leaks, or execution of attacker-controlled code. Zoom rates the severity as high, requiring user interaction for exploitation, contrasting with researchers' critical assessment.
Users are advised to update their Zoom software and implement security measures, such as using passcodes and authentication, to mitigate risks.