Researchers have found three vulnerabilities in the popular Zoom meeting platform that could let one meeting participant attack another through malicious collaboration data.

The vulnerabilities, tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415, affect the code Zoom uses to process annotation data shared during meetings. The researchers named the set of flaws “Zoomsday.”

Affected applications are:

Zoom Workplace on all supported platforms before version 7.1.5 and 7.0.6, depending on the release branch

Zoom Workplace VDI Client for Windows before versions 7.0.11 and 6.6.16, depending on the release branch