Office business team concept. Video conference call using laptop with remote working teammates
time 1 minute read

Zoom Clients – High Severity Vulnerability Requires Immediate Update

A high-severity vulnerability, CVE-2026-53413, has been identified in multiple Zoom products, including Zoom Workplace, Zoom Workplace VDI Client, Zoom Rooms, and Zoom Meeting SDK components.

This vulnerability is caused by a missing bounds check in the annotator function, which can create a buffer overwrite condition. If exploited, a malicious meeting participant may be able to achieve remote code execution on another participant’s system over the network.


Risk and impact

• A malicious meeting participant may be able to execute code on another participant’s device.

• Exploitation can occur through network access during a Zoom meeting session.

• Successful exploitation could affect the confidentiality, integrity, and availability of affected systems.

• Organizations using vulnerable Zoom clients, VDI clients, Zoom Rooms, or Meeting SDK implementations may be at risk until updates are applied.

• The vulnerability affects multiple supported Zoom product families across desktop, VDI, and meeting room environments.

Resolution
Zoom Workplace Client has resolved this vulnerability in version 7.1.5 and later, or version 7.0.6 and later in the 7.0 branch. Zoom Workplace VDI Client for Windows has resolved this vulnerability in version 7.0.11 and later, or version 6.6.16 and later in the 6.6 branch.


Required action
We strongly urge all users to update Zoom Workplace Client to version 7.1.5 and Zoom Workplace VDI Client to version 7.0.11. We also encourage users to upgrade Zoom VDI Universal Plugin to version 7.0.11 to avoid VDI Client compatibility issues.

Update packages have already been synchronized and are available in your environment for deployment. Failure to apply this update may leave systems vulnerable to exploitation.

If you need help understanding or implementing these recommendations, Helient is here to help. Please contact our team through the ticketing system at service@helient.com.


Source: https://www.zoom.com/en/trust/security-bulletin/zsb-26015/