CVE Tools

Zoom Patches Zero-Click Code Execution Vulnerability

SecurityWeekBy Ionut Arghire

PoC publicZoom WorkplaceZoom Rooms

Our summary

Zoom has deployed security updates addressing four vulnerabilities across its Workplace and Rooms products, most notably CVE-2026-53413. This critical memory corruption flaw in the annotator function enables zero-click remote code execution, allowing attackers to compromise participants' machines without any interaction. The advisory also covers a denial-of-service issue and a path traversal vulnerability that results in information disclosure.

To mitigate these risks, users should upgrade to Zoom Workplace 7.1.5 or 7.0.6, Zoom Rooms 7.1.5, and the corresponding VDI client versions.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store