NCSC-2026-0293 [1.00] [M/H] Vulnerabilities patched in Zoom
Zoom has patched vulnerabilities in Zoom Clients and Zoom VDI Client software. The Zoom Clients contain multiple vulnerabilities in the annotator function. One involves a missing bounds check that can lead to a buffer overwrite, allowing an external participant via network access to potentially execute arbitrary code on another participant's device. Another vulnerability in the same function involves a buffer over-read, which can cause a denial-of-service through crashes or service interruptions during meetings. Additionally, there is a use-after-free vulnerability in the annotator function that can also be exploited by an external participant via network access to execute arbitrary code on another participant's device. Furthermore, the Zoom VDI Client and its associated plugins contain a path traversal vulnerability that can be exploited by an authenticated user with local access. This vulnerability arises from improper validation of file paths, allowing access to files outside the intended directory structure, which can lead to unauthorized access to data.
CSIRTS triage
- What
- Multiple vulnerabilities including buffer overwrite, buffer over-read, use-after-free, and path traversal affect Zoom annotation functions and VDI client.
- Who is affected
- External participants in Zoom meetings can trigger code execution; authenticated local users of VDI Client can exploit path traversal.
- Urgency
- High priority; active exploitation demonstrated with remote code execution leading to crypto miner installation.
- Action
- Update Zoom Clients and VDI Client to patched versions immediately.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Zoom Clients and Zoom VDI Client
Get an email when a new Zoom Clients and Zoom VDI Client advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0293
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2026-534135.6% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 92% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-534140.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-534150.55% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 43% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-534160.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-53413 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-53414 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-53415 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-53416 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Zoom Video Communications Workplace and Rooms: Multiple Vulnerabilitiescert-bund
- unknownZoom Products Multiple Vulnerabilitieshkcert
- highCVE-2026-53416: Path traversal in Zoom VDI Client and Plugins may allow an authenticated user to conduct infor…nvd
- highCVE-2026-53415: Use after Free in the annotator function of Zoom Clients may allow a meeting participant to ac…nvd
- mediumCVE-2026-53414: Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which …nvd
- highCVE-2026-53413: Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which…nvd
More from NCSC-NL Advisories
- unknownNCSC-2026-0303 [1.01] [M/H] Vulnerabilities patched in GitLab by GitLab Inc.2026-08-25
- unknownNCSC-2026-0326 [1.00] [M/H] Vulnerabilities patched in Keycloak2026-08-25
- unknownNCSC-2026-0325 [1.00] [M/H] Vulnerabilities patched in Atlassian products2026-08-24
- unknownNCSC-2026-0324 [1.00] [M/H] Vulnerability fixed in Zimbra Collaboration Suite2026-08-23
- unknownNCSC-2026-0323 [1.00] [M/H] Vulnerabilities fixed in Cisco Secure Workload2026-08-21