logo

“Zoomsday” flaws could let one Zoom participant attack another

ID: 162d6fa5-b9a4-5906-aae4-d238cf58e2d1

STIX ID: report--162d6fa5-b9a4-5906-aae4-d238cf58e2d1

Feed Name: Malwarebytes Blog

Threat Score
75/100

Date Published: 2026-08-12

Date Updated: 2026-08-12

...
...

Researchers disclosed three memory-safety vulnerabilities in Zoom's annotation parser (CVE-2026-53413, CVE-2026-53414, CVE-2026-53415) — dubbed “Zoomsday” — where a malicious meeting participant could send crafted collaboration data to crash clients, leak information, or achieve remote code execution; affected products include multiple Zoom Workplace, VDI, Rooms and Meeting SDK releases. The report highlights differing severity assessments (researchers: Critical; Zoom: High), and advises updating Zoom, restricting meeting access/features, and using anti-malware and device-management controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.