THREATOPS
THREAT OPSThreat News › Zoom Zero-Click RCE Flaws Allow Any Meeting Attendee to Compromise All Participants

Zoom Zero-Click RCE Flaws Allow Any Meeting Attendee to Compromise All Participants

medorca_securityPublished 2026-08-12

<p>Executive Summary Multiple critical memory corruption vulnerabilities (CVE-2026-53413, CVSS 8.3/9.0 and CVE-2026-53415, CVSS 8.3/9.0) were disclosed affecting Zoom Workplace clients across all platforms, allowing attackers to achieve zero-click remote code execution against every participant in a meeting via malicious annotation messages. Due to the potential for full device compromise without

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://orca.security/resources/research-pod/zoom-zero-click-rce-vulnerability-orca-security/