If you use Zoom for work calls, doctor appointments or classes, check your version today. Zoom has patched a set of flaws in its annotation feature that let one participant in a live meeting run code on another participant’s machine — no click, no download, nothing required of the victim beyond being in the call. The fixes shipped on 11 August 2026, and the only thing standing between you and the bug is whether your app has actually updated itself.

What the Zoom security update actually fixes
Three of the four bugs sit in Zoom’s annotator — the tool that lets people draw on a shared screen. Per Zoom’s own bulletins:
- CVE-2026-53413 (ZSB-26015) — a missing bounds check allowing a buffer over-write. CVSS 8.3, rated High. Zoom’s description: it “may allow a meeting participant to achieve remote code execution of another participant via network access.”
- CVE-2026-53415 (ZSB-26017) — a use-after-free in the same function, also CVSS 8.3, also leading to remote code execution.
- CVE-2026-53414 (ZSB-26016) — a buffer over-read, CVSS 6.5, usable to crash another participant’s client.
- CVE-2026-53416 — a path traversal issue in the Workplace VDI client and plugins, leading to information disclosure.
The first two were reported by Idan Levcovich of A Security; the use-after-free is credited to Zoom’s own offensive security team, which had already found it. A Security nicknamed the research “Zoomsday” and says it disclosed to Zoom in June 2026, with client-side and server-side fixes deployed before publication.
How bad is it, honestly
Bad enough to update, not a reason to panic. A Security’s write-up describes the attack in blunt terms:
The exploit enables attackers to either join or host a meeting, target any participant, and take over their machine with no required action from the victim and no visual cue indicating the compromise.
Two caveats worth stating plainly, because a lot of the coverage has not. First, the attacker has to be in your meeting — this is not something a stranger can fire at your PC over the internet. Second, Zoom’s own CVSS vector for both RCE bugs is CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H, which flags high attack complexity and, notably, user interaction required. “Zero-click” is the researchers’ and the press’s framing, and it is fair in the sense that the victim never clicks anything malicious. It is not Zoom’s own wording. Either way, if you take calls with people you don’t fully trust — recruiters, vendors, public webinars, online classes — this matters to you.
Which version you need
For ordinary users the number to care about is the Zoom Workplace client:
- Zoom Workplace — all supported platforms before 7.1.5 and 7.0.6 in their respective branches are affected. A Security states the bug is present in all versions up to and including 7.0.5.
- Zoom Workplace VDI Client for Windows — before 7.0.11 and 6.6.16 in their respective branches.
- Zoom Rooms and Meeting SDK — Zoom’s bulletins list these as before 7.1.0 for CVE-2026-53413 and CVE-2026-53414, and before 7.1.5 for CVE-2026-53415, so the safe target is 7.1.5.
To check on Windows or Mac, open Zoom, click your profile picture in the top-right corner and use the update option in that menu. On Android and iOS, update through the Play Store or App Store — mobile clients were affected too. Fresh installers are at zoom.us/download. It is worth doing the same check on your other calling apps — Apple shipped a screen-sharing security fix in macOS Tahoe 26.6.1 for a comparable reason earlier this month.
The part Zoom should be uncomfortable about
The annotation protocol at the centre of this is proprietary and undocumented, and every Zoom client automatically parses whatever it receives over it. That combination means users carry the risk of code they are not allowed to inspect, and the only defence offered to them is checking a version number. A Security also says the whole thing — finding the flaw and building a working exploit — took fewer than 20 prompts on publicly available AI models in under 24 hours. Closed-source video calling software that A Security notes is used by 70% of the Fortune 100, and by ordinary people to talk to their doctors and lawyers, cannot keep leaning on obscurity as a security layer when the cost of breaking it has fallen that far.
Sources: Zoom security bulletin ZSB-26015, A Security, SecurityWeek
