Zoomsday RCE Flaw Patched in Zoom Clients
A buffer overflow in Zoom's annotator function (CVE-2026-53413), dubbed Zoomsday, could let a meeting participant achieve remote code execution on another participant without interaction.
CIS/MS-ISAC issued an advisory covering a vulnerability in Zoom Clients caused by a missing bounds check in the annotator function, resulting in a buffer over-write. An attacker who joins or hosts a Zoom meeting could exploit this flaw to execute code on another participant's device with no user interaction required, potentially stealing data, activating cameras or microphones, and installing malware. In large meetings, a single malicious action could compromise multiple participants simultaneously.
The vulnerability, tracked as CVE-2026-53413 and nicknamed "Zoomsday" by open-source reporting, affects Zoom Workplace clients across all supported platforms prior to versions 7.1.5 and 7.0.6, the Zoom Workplace VDI Client for Windows prior to 7.0.11 and 6.6.16, Zoom Rooms prior to 7.1.0, and Zoom Meeting SDK prior to 7.1.0. There are currently no reports of in-the-wild exploitation, but given the network-based, zero-click nature of the flaw and Zoom's widespread enterprise use, organizations should prioritize patching.
MS-ISAC recommends applying vendor updates immediately after testing, alongside standard vulnerability management practices including patch management, vulnerability scanning, network segmentation, least-privilege enforcement, and anti-exploitation features.
Mentioned in this report
Source reporting: https://www.cisecurity.org/advisory/a-vulnerability-in-zoom-clients-could-allow-for-remote-code-execution_2026-081
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free