CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

NCSC-2026-0293 [1.00] [M/H] Vulnerabilities patched in Zoom

unknownpublic exploitCVE-2026-53413CVE-2026-53414CVE-2026-53415CVE-2026-53416
Zoom has patched vulnerabilities in Zoom Clients and Zoom VDI Client software. The Zoom Clients contain multiple vulnerabilities in the annotator function. One involves a missing bounds check that can lead to a buffer overwrite, allowing an external participant via network access to potentially execute arbitrary code on another participant's device. Another vulnerability in the same function involves a buffer over-read, which can cause a denial-of-service through crashes or service interruptions during meetings. Additionally, there is a use-after-free vulnerability in the annotator function that can also be exploited by an external participant via network access to execute arbitrary code on another participant's device. Furthermore, the Zoom VDI Client and its associated plugins contain a path traversal vulnerability that can be exploited by an authenticated user with local access. This vulnerability arises from improper validation of file paths, allowing access to files outside the intended directory structure, which can lead to unauthorized access to data.

CSIRTS triage

What
Multiple vulnerabilities including buffer overwrite, buffer over-read, use-after-free, and path traversal affect Zoom annotation functions and VDI client.
Who is affected
External participants in Zoom meetings can trigger code execution; authenticated local users of VDI Client can exploit path traversal.
Urgency
High priority; active exploitation demonstrated with remote code execution leading to crypto miner installation.
Action
Update Zoom Clients and VDI Client to patched versions immediately.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Zoom Clients and Zoom VDI Client

Get an email when a new Zoom Clients and Zoom VDI Client advisory drops — max one per day, one-click unsubscribe.

Details

Source
NCSC-NL Advisories (NL · national-cert · site)
Severity
unknown
Published
2026-08-12
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0293

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-53413coverage & exploitation statusNVD · CVE.org
CVE-2026-53414coverage & exploitation statusNVD · CVE.org
CVE-2026-53415coverage & exploitation statusNVD · CVE.org
CVE-2026-53416coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from NCSC-NL Advisories