THREAT OPS › Threat News › Zoom Zero-Click RCE Flaws Allow Any Meeting Attendee to Compromise All Participants
Zoom Zero-Click RCE Flaws Allow Any Meeting Attendee to Compromise All Participants
<p>Executive Summary Multiple critical memory corruption vulnerabilities (CVE-2026-53413, CVSS 8.3/9.0 and CVE-2026-53415, CVSS 8.3/9.0) were disclosed affecting Zoom Workplace clients across all platforms, allowing attackers to achieve zero-click remote code execution against every participant in a meeting via malicious annotation messages. Due to the potential for full device compromise without
MITRE ATT&CK techniques
- VulnerabilitiesT1588.006
Indicators of compromise
- CVE-2026-53413cve
- CVE-2026-53415cve