Vulnerability intelligence
CVE-2026-53414
Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting participant to conduct a denial of service on another participant via network access.
CVSS Score
6.5
Medium
EPSS — Exploit Probability
0.4%
Riskier than 26% of all CVEs · checked 2026-09-24
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
3 articles across 3 outlets · first covered Aug 11, 2026 · latest Aug 12, 2026
Coverage timeline
-
Zoom patches critical annotation flaws after Zoomsday discoverywww.malwarebytes.com · Aug 12, 2026
-
Zoom patches critical zero click flaw Zoomsday threatening meetingssecurityaffairs.com · Aug 11, 2026
-
Zoom Patches Zero-Click Code Execution Vulnerabilitywww.securityweek.com · Aug 11, 2026