ON Tuesday, Zoom announced patches for four vulnerabilities, including a critical flaw that allowed zero-click remote code execution (RCE) due to a memory corruption issue in the annotator function. The most severe vulnerability, CVE-2026-53413, enabled an attacker to execute code on another participant's machine without their interaction. Other noted vulnerabilities include CVE-2026-53414, which could lead to a denial-of-service (DoS) attack, and CVE-2026-53415, a use-after-free flaw.
Zoom's updates are now available for various platforms including Workplace and Meeting SDK versions. The increased security measures come in response to the identification of these flaws by A Security, which emphasized the need for patches before public disclosure.