securityaffairs.com 11 Aug 2026, 17:48 UTC

Zoom patches critical zero click flaw Zoomsday threatening meetings

Zoom patches critical zero click flaw Zoomsday threatening meetings
CyberSIXT Evidence Panel
Primary Source zoom.com
CISA KEV Not in KEV
Patch Patch Status Unknown

ZOOM has released patches for several vulnerabilities, including a critical zero-click flaw labeled "Zoomsday" (CVE-2026-53413) linked to its annotation feature. This vulnerability allows an attacker to execute code on another participant's device during a meeting without any user interaction. The flaws potentially enable data theft, activation of microphones and cameras, and malware installation.

A Security, which discovered the vulnerabilities, highlighted the risks posed by the annotation protocol and called attention to additional issues including CVE-2026-53414 and CVE-2026-53415. Zoom has begun rolling out security updates to mitigate these risks across all supported platforms.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline