CVE-2026-53415 – Zoom Clients

CVSS 8.3 IMPORTANT High with EoP or RCE – Expedited Deployment

“A malicious meeting participant could turn Zoom’s annotation features into a path for code execution or disruption.”

Zoom Clients are affected by three vulnerabilities in the annotator functionality. CVE-2026-53413 has a CVSS score of 8.3, High severity, and may allow a meeting participant to remotely execute code on another participant’s system through a buffer overwrite. CVE-2026-53414 has a CVSS score of 6.5, Medium severity, and may allow denial of service through a buffer over-read. CVE-2026-53415 has a CVSS score of 8.3, High severity, and may allow remote code execution through a use-after-free condition.

Updated Zoom Clients address these annotation-related vulnerabilities and reduce the risk of participant-to-participant compromise and service disruption.

Key Details

Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
CWE Classification
CWE-416
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.