
ZOOM has issued security updates for a critical zero‑click vulnerability nicknamed Zoomsday that could let an attacker run code on another participant’s device during a meeting without any action from the victim according to SecurityAffairs. The flaw resides in the annotation feature and allows remote code execution with no user interaction.
The most serious issue, tracked as CVE-2026-53413, is a high‑severity memory corruption bug in the annotator that enables arbitrary code execution as reported by SecurityWeek. A second flaw, CVE-2026-53414, carries a medium rating and could be leveraged for denial‑of‑service attacks, while CVE-2026-53415 is a high‑severity use‑after‑free weakness. Together they affect the annotation handling across Zoom clients.
Exploiting Zoomsday requires only sending a specially crafted annotation packet; no click or other interaction from the target is needed. Once triggered, an attacker could gain control of the microphone and camera, exfiltrate data or drop malware onto the host. To date, Zoom has not observed any active exploitation of these bugs in the wild.
The vulnerabilities were disclosed to Zoom by the research group A Security, which warned that the annotation protocol exposed a broad attack surface. Zoom has begun rolling out patches for all supported platforms, including the Workplace application and the Meeting SDK. No threat actors have been publicly linked to the flaws so far.
Defenders should ensure every endpoint runs the latest Zoom version released after the advisory, enabling automatic updates where possible. The specific build numbers and download links are available in Zoom’s official security bulletin here.
Administrators are also advised to review annotation permissions in meetings, consider disabling guest annotation if it is not required, and monitor logs for unexpected annotation activity that could signal an attempt to exploit the patched issues. Regularly checking for future Zoom advisories will help stay ahead of similar threats.