Zoom has patched three memory corruption flaws in its annotation feature that allowed any meeting participant to run code on another attendee’s device with no interaction. The fixes shipped in June and July 2026, roughly two months before the research was made public.
Zoom has patched three flaws in the annotation tools used during screen sharing that let anyone on a call run code on another participant’s device. No click was needed and nothing visible happened. The fixes shipped in June and July.
That timing is worth stating plainly, because the story has been written up as an emergency. Zoom closed the holes roughly two months before the research went public, so anyone on a current client is already covered.
The fixed builds are Zoom Workplace 7.1.5 and 7.0.6, Rooms and the Meeting SDK at 7.1.5, and the Windows VDI client at 7.0.11 and 6.6.16. Anything older remains exposed.
The severity is also softer than reported. A Security, the firm that found the bugs, scored all three at 9.0 out of 10. Zoom rates CVE-2026-53413 and CVE-2026-53415 at 8.3 and CVE-2026-53414 at 6.5.











