TL;DR
Zoom released four security bulletins on August 11, 2026. Two of the flaws allow remote code execution against meeting participants. Each Zoom security vulnerability now has a fix, so users should update right away.
- Product: Zoom Communications (2 products)
- Vulnerabilities: 4 flaws (CVE-2026-53413, CVE-2026-53415, CVE-2026-53416, CVE-2026-53414)
- Highest severity: 8.3 (High · CVSSv3)
- Worst impact: Buffer Over-write
- Status: No confirmed exploitation yet; patches available
- Action: Update to 7.0.11 now
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-53413 | 8.3 | CWE-787 | — | Not exploited |
| CVE-2026-53415 | 8.3 | CWE-416 | — | Not exploited |
| CVE-2026-53416 | 7.1 | CWE-23 | 7.0.11 | Not exploited |
| CVE-2026-53414 | 6.5 | CWE-126 | — | Not exploited |
Why These Zoom Flaws Matter
Zoom serves hundreds of millions of meeting participants worldwide. A flaw that spreads from one attendee to another raises the stakes. Three of these four bugs carry a High severity rating.
How the Attacks Work
Three flaws share the same root: the annotator function. It fails to check bounds or free memory correctly.
Remote Code Execution Bugs
CVE-2026-53413 is a buffer over-write, while CVE-2026-53415 is a use-after-free. Both score CVSS 8.3. Each may let one meeting participant run code on another participant’s machine over the network.
Denial of Service and Path Traversal
CVE-2026-53414 is a buffer over-read that can crash a target’s client. Separately, CVE-2026-53416 is a path traversal in the VDI client. It allows an authenticated user to read files through local access.
Affected Versions
The client bugs affect Zoom Workplace before 7.1.5 and 7.0.6, plus Zoom Rooms and the Meeting SDK. The VDI path traversal affects Workplace VDI Client for Windows before 7.0.11 and 6.6.15. Zoom credits its own Offensive Security team for the discoveries.
Patch and Mitigation Steps
Update every Zoom client to the latest release from the download center. Review the bulletins for ZSB-26015, ZSB-26016, ZSB-26017, and ZSB-26018 for exact versions.
Zoom reports no evidence of exploitation in the wild for any Zoom security vulnerability in this batch. Fast patching still closes the risk before that changes.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.