ZOOM has released patches for several vulnerabilities, including a critical zero-click flaw labeled "Zoomsday" (CVE-2026-53413) linked to its annotation feature. This vulnerability allows an attacker to execute code on another participant's device during a meeting without any user interaction. The flaws potentially enable data theft, activation of microphones and cameras, and malware installation.
A Security, which discovered the vulnerabilities, highlighted the risks posed by the annotation protocol and called attention to additional issues including CVE-2026-53414 and CVE-2026-53415. Zoom has begun rolling out security updates to mitigate these risks across all supported platforms.