securityaffairs.com 8/11/2026, 6:21:01 PM · external

Zoom patches critical zero click flaw Zoomsday threatening meetings

Zoom patches critical zero click flaw Zoomsday threatening meetings
Developing story vulnerability 2 articles tracked
Zoom patches critical zero-click flaw (CVE-2026-53413) in annotation feature
CyberSIXT Evidence Panel

ZOOM has released patches for several vulnerabilities, including a critical zero-click flaw labeled "Zoomsday" (CVE-2026-53413) linked to its annotation feature. This vulnerability allows an attacker to execute code on another participant's device during a meeting without any user interaction. The flaws potentially enable data theft, activation of microphones and cameras, and malware installation.

A Security, which discovered the vulnerabilities, highlighted the risks posed by the annotation protocol and called attention to additional issues including CVE-2026-53414 and CVE-2026-53415. Zoom has begun rolling out security updates to mitigate these risks across all supported platforms.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline