• Sources: primary, bulletin index, discussion
  • Summary: Zoom bulletin ZSB-26017, published 2026-08-11, records CVE-2026-53415 at CVSS 3.1 8.3 with vector CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H, and describes a use-after-free in the annotator function that may allow a meeting participant to achieve remote code execution against another participant over network access. Affected products are Zoom Workplace before 7.1.5 and 7.0.6 in their respective branches on all supported platforms, Zoom Workplace VDI Client for Windows before 7.0.11 and 6.6.16, Zoom Rooms before 7.1.5, and Zoom Meeting SDK before 7.1.5. Zoom credits Zoom Offensive Security and published three further bulletins the same day covering CVE-2026-53413, CVE-2026-53414, and CVE-2026-53416, none of the four rated Critical.
  • Why it matters: The precondition is attending a meeting, which is the ordinary case in most organisations, and the remedy is a client update on every endpoint rather than a server-side change.

send feedback on this story