Vulnerability intelligence
CVE-2026-53415
Use after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve remote code execution of another participant via network access.
CVSS Score
8.3
High
EPSS — Exploit Probability
0.5%
Riskier than 45% of all CVEs · checked 2026-09-24
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
4 articles across 4 outlets · first covered Aug 11, 2026 · latest Aug 12, 2026
Coverage timeline
-
Zoom patches critical annotation flaws after Zoomsday discoverywww.malwarebytes.com · Aug 12, 2026
-
Zoom fixes two remote code execution bugs in annotator functionsecurityonline.info · Aug 12, 2026
-
Zoom patches critical zero click flaw Zoomsday threatening meetingssecurityaffairs.com · Aug 11, 2026
-
Zoom Patches Zero-Click Code Execution Vulnerabilitywww.securityweek.com · Aug 11, 2026