Multiple Vulnerabilities in Zoom Products
20 August 2026
Attackers can exploit multiple vulnerabilities in Zoom products to perform remote code execution, denial of service or disclose sensitive information. Users and administrators of affected products are advised to apply the latest security updates promptly.
Background
Security updates have been released to address multiple vulnerabilities (CVE-2026-53413, CVE-2026-53414, CVE-2026-53415, CVE-2026-53416) affecting its products. These vulnerabilities have a Common Vulnerability Scoring System (CVSS v3.1) score of: CVE-2026-53413 at 8.3, CVE-2026-53414 at 6.5, CVE-2026-53415 at 8.3 and CVE-2026-53416 at 7.1, out of 10.
Impact
Successful exploitation of these vulnerabilities could lead to the following:
CVE-2026-53413: Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting participant to achieve remote code execution of another participant via network access.
CVE-2026-53414: Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting participant to conduct a denial of service on another participant via network access.
CVE-2026-53415: Use after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve remote code execution of another participant via network access.
CVE-2026-53416: Path traversal in Zoom VDI Client and Plugins may allow an authenticated user to conduct information disclosure via local access.
Affected Products
These vulnerabilities affect the following products and versions:
CVE-2026-53413:
Zoom Workplace on all supported platforms before versions 7.1.0 and 7.0.6 in their respective branches
Zoom Workplace VDI Client for Windows before versions 7.0.11 and 6.6.16 in their respective branches
Zoom Rooms on all supported platforms before version 7.1.0
Zoom Meeting SDK on all supported platforms before version 7.1.0
Zoom Video SDK on all supported platforms before version 2.6.0
CVE-2026-53414:
Zoom Workplace on all supported platforms before versions 7.1.0 and 7.0.6 in their respective branches
Zoom Workplace VDI Client for Windows before versions 7.0.11 and 6.6.16 in their respective branches
Zoom Rooms on all supported platforms before version 7.1.0
Zoom Meeting SDK on all supported platforms before version 7.1.0
Zoom Video SDK on all supported platforms before version 2.6.0
CVE-2026-53415:
Zoom Workplace on all supported platforms before versions 7.1.5 and 7.0.6 in their respective branches
Zoom Workplace VDI Client for Windows before versions 7.0.11 and 6.6.16 in their respective branches
Zoom Rooms on all supported platforms before version 7.1.5
Zoom Meeting SDK on all supported platforms before version 7.1.5
Zoom Video SDK on all supported platforms before version 2.6.5
CVE-2026-53416:
Zoom Workplace VDI Client for Windows before versions 7.0.11 and 6.6.15 in their respective branches
Zoom Workplace VDI Plugins on all supported platforms before 7.0.11 and 6.6.15 in their respective branches
Recommendations
Users and administrators of affected products are advised to update to the latest versions promptly.
References
https://www.securityweek.com/zoom-patches-zero-click-code-execution-vulnerability/
https://www.zoom.com/en/trust/security-bulletin/zsb-26015/
https://www.zoom.com/en/trust/security-bulletin/zsb-26016/
