CVE-2026-53413
CVSS 8.3 HIGH: missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting…
Vulnerabilities · 47 days ago
Dutch NCSC said Zoom has patched four annotation-related flaws in Zoom Client and Zoom VDI Client, including CVE-2026-53413, after the bugs were already public. The advisory moves the story from discovery to deployment: the question now is which fleets have actually picked up the fixes.
The bug sits in Zoom's annotator protocol, where one participant's drawing or text messages are parsed by another client's app as normal collaboration data. That trust boundary matters because malformed annotation traffic can crash the receiving client or overwrite memory, so one meeting participant can reach another attendee's device through the meeting itself.
For organizations that rely on screen sharing and live annotation, the exposed surface is the collaboration channel, not just the host machine or meeting room device. Until the patched clients are widely in place, any meeting with an unpatched participant keeps that peer-to-peer trust path in play.
CVSS 8.3 HIGH: missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting…
CVSS 6.5 MEDIUM: missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting…
5 sources covering this story
Kwetsbaarheden verholpen in Zoom
Zoom heeft kwetsbaarheden verholpen in Zoom Clients en Zoom VDI Client software.
Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client
Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client | Read more hacking news on The Hacker News cybersecurity news website and learn how to protect against cyberattacks and software vulnerabilities.
Zoom zero-click RCE flaws allow attackers to compromise meeting participants
A single AI-assisted researcher discovered the massive blast-radius vulnerabilities using fewer than 20 prompts on publicly available models in less than 24 hours.
Zoom Patches Zero-Click Code Execution Vulnerability
Impacting Zoom annotation, the bug could be exploited by a meeting participant to execute code on another participant’s machine.
Vulnerabilità in prodotti Zoom
Rilevate 4 nuove vulnerabilità, di cui 3 con gravità “alta”, nel software Zoom.
Part of the PlainSec briefing for 2026-08-12