CVE-2026-53413
CVSS 8.3 HIGH: missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting…
Vulnerabilities & Exploits
Dutch NCSC said Zoom has patched four annotation-related flaws in Zoom Client and Zoom VDI Client, including CVE-2026-53413, after the bugs were already public. The advisory moves the story from discovery to deployment: the question now is which fleets have actually picked up the fixes.
The bug sits in Zoom's annotator protocol, where one participant's drawing or text messages are parsed by another client's app as normal collaboration data. That trust boundary matters because malformed annotation traffic can crash the receiving client or overwrite memory, so one meeting participant can reach another attendee's device through the meeting itself.
For organizations that rely on screen sharing and live annotation, the exposed surface is the collaboration channel, not just the host machine or meeting room device. Until the patched clients are widely in place, any meeting with an unpatched participant keeps that peer-to-peer trust path in play.
5 sources · Aug 12
CVSS 8.3 HIGH: missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting…
CVSS 6.5 MEDIUM: missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting…
NCSC-NL Advisories
Kwetsbaarheden verholpen in Zoom
Zoom heeft kwetsbaarheden verholpen in Zoom Clients en Zoom VDI Client software.
originalThe Hacker News
Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client
Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client | Read more hacking news on The Hacker News cybersecurity news website and learn how to protect against cyberattacks and software vulnerabilities.
originalCSO Online
Zoom zero-click RCE flaws allow attackers to compromise meeting participants
A single AI-assisted researcher discovered the massive blast-radius vulnerabilities using fewer than 20 prompts on publicly available models in less than 24 hours.
originalPart of the PlainSec briefing for 2026-08-12
Every edition of this story: Zoom Fixes Four Annotation Flaws After Disclosure