What happened
Zoom released fixes for four vulnerabilities in its Workplace apps, disclosed August 11 alongside research from the security firm A Security, which discovered the most serious bug and named it Zoomsday. That flaw, CVE-2026-53413, is a memory-corruption issue in Zoom's annotation engine — the feature that lets participants draw on a shared screen. Because every Zoom client automatically parses incoming annotation data, a malicious participant could send a crafted message that corrupts another participant's device memory and runs code on it, with no click, download, or approval from the victim. The same code ships in Zoom's apps across Windows, macOS, Linux, iOS, and Android, so all platforms were affected. The companion flaws include a denial-of-service bug in the text annotator and a use-after-free issue Zoom had already found internally, plus a path-traversal bug in VDI clients. Fixes landed in Zoom Workplace 7.1.5 and 7.0.6, Rooms 7.1.5, and the Meeting SDK 7.1.5. No exploitation in the wild had been reported at disclosure.
Why it matters for your business
Video calls are where sensitive business happens — client consultations, financials, personnel matters. A zero-click flaw is the worst kind because employee vigilance cannot help; simply being in a meeting was enough exposure. The realistic risk for a small firm is not a targeted attack but the long tail of unpatched apps: Zoom clients that employees installed themselves and that nobody updates.
What to do about it
- Update Zoom to version 7.1.5 or later on every device, including personal phones used for work calls
- Fully quit and restart the app so the update actually applies
- If you manage devices centrally, push the update rather than waiting on users
- Take this as a reminder to keep all meeting software — not just Zoom — in the automatic-update lane
