Zoom Patches Zero-Click Code Execution Vulnerability
PoC publicZoom WorkplaceZoom RoomsOur summary
Zoom has deployed security updates addressing four vulnerabilities across its Workplace and Rooms products, most notably CVE-2026-53413. This critical memory corruption flaw in the annotator function enables zero-click remote code execution, allowing attackers to compromise participants' machines without any interaction. The advisory also covers a denial-of-service issue and a path traversal vulnerability that results in information disclosure.
To mitigate these risks, users should upgrade to Zoom Workplace 7.1.5 or 7.0.6, Zoom Rooms 7.1.5, and the corresponding VDI client versions.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.