Threat reportVulnerabilityTL-2026-2001

"Zoomsday" Flaws (CVE-2026-53413, CVE-2026-53414, CVE-2026-53415) Let One Zoom Meeting Participant Attack Another

criticalPATCHED

"Zoomsday" Flaws (CVE-2026-53413, CVE-2026-53414 (TL-2026-2001), also tracked as Zoomsday, is a critical-severity software vulnerability scored CVSS 8.3, first published 2026-08-12. It has no confirmed attribution, affects Zoom Communications Zoom Workplace, references 3 CVEs (CVE-2026-53413, CVE-2026-53414, CVE-2026-53415), maps to 10 MITRE ATT&CK techniques (T1005, T1106, T1113), and is covered by 9 detection rules and 15 indicators of compromise.

CVSS
8.3/10Critical
CVEs
3Referenced vulnerabilities
Techniques
10MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
15Indicators of compromise

Key facts for TL-2026-2001

Threat ID
TL-2026-2001
Also known as
Zoomsday
Severity
CRITICAL
CVSS
8.3 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H)
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, government administration, financial-services, health, education, professional-services
Target regions
Global
Detection rules
9
Indicators of compromise
15

Malware and tooling in "Zoomsday" Flaws (CVE-2026-53413, CVE-2026-53414

Malware and tooling: Frida, IDA

How "Zoomsday" Flaws (CVE-2026-53413, CVE-2026-53414 works

Three memory-safety bugs in the annotation parser shared by Zoom Workplace, Zoom Rooms, the Zoom Meeting SDK, and the Zoom Workplace VDI Client for Windows let one meeting participant send crafted annotation protocol data to crash another participant's client, leak process memory, or achieve zero-click remote code execution. Israeli research firm A Security ("Zoomsday") built working exploits in under a day using AI-assisted reverse engineering; Zoom shipped client and server-side fixes between June and August 2026 and there is no evidence of in-the-wild exploitation.

On 2026-08-11 Zoom published three coordinated security bulletins — ZSB-26015, ZSB-26016, and ZSB-26017 — for a cluster of annotation-feature vulnerabilities that Israeli offensive-security firm A Security named "Zoomsday." All three flaws live in the code that deserializes annotation/whiteboard objects Zoom's proprietary protocol passes directly between meeting participants, meaning one attendee can attack another attendee's client without going through any server-side content filter that would normally apply to shared files or chat.

CVE-2026-53413 (CVSS 3.1: 8.3, CWE-787 Out-of-bounds Write) is a stack buffer overflow in the `CAnnoFormatBlock::Deserialize` routine (found in the Android client's `libannotate.so` and its cross-platform equivalents): the function contains four fixed 128-byte buffers but trusts a wire-supplied 32-bit character count when copying into them, so an oversized count overwrites adjacent stack memory including saved registers and the return address. A Security's proof-of-concept sent a 745-byte AddObj protocol data unit (opcode 0x10001, object flags bit 3 for TextFrame) with an oversized fourth channel count (0x100, eight times the 128-byte buffer capacity) to overflow a 704-byte `CAnnoTextFrame` stack variable; on macOS arm64 they hijacked the function epilogue to control registers X19-X30 and pivoted through a single shared-cache gadget (`MOV X0,X19; MOV X1,X21; BL execvp`) to launch Safari with no PAC or stack-canary protection engaged. Register planting placed the gadget address in the link register (X30), the path `/Applications/Safari.app/Contents/MacOS/Safari` in X19, and an argv pointer `{path, NULL}` in X21; one leaked pointer was enough to rebase the entire shared-cache block as a unit and defeat ASLR. On Android, the team sprayed `ExtChild` objects (592-byte heap size class) to place a controlled neighbor object adjacent to the overflow source, then corrupted only the low, ASLR-invariant byte of that neighbor's C++ vtable pointer so a subsequent virtual-call dispatch redirected within the vulnerable module without needing a separate information leak; the corruption was triggered via the un-gated teardown path reachable from RemoveObj/ModifyObj wire operations, which invoke a destructor virtual call on the sprayed object.

CVE-2026-53414 (CVSS 3.1: 6.5, CWE-126 Buffer Over-read) is a companion flaw in the same annotator: Zoom allocates a glyph buffer sized `2 × count + 2` bytes from an attacker-declared character count but fills it from however many bytes actually arrived on the wire (a short body), exposing the uninitialized/adjacent heap tail back to the sender. That leaked memory can contain live code pointers, vtable addresses, and resource strings useful for defeating ASLR in a follow-on exploit chain, and at minimum reliably crashes the receiving client (denial of service).

CVE-2026-53415 (CVSS 3.1: 8.3, CWE-416 Use After Free) involves annotation message type 75 (`CAnnoObjAutoMetaShape`), which deserializes linked-list pointers from network data and unlinks them without validation, producing a write-what-where primitive that can also be driven to remote code execution. Unlike the other two, this bug was found independently by Zoom's own internal Offensive Security team (credited on ZSB-26017) before A Security's report; A Security's own researcher Lidor Elias is credited for its triage.

Underlying all three is a dispatcher validation gap in `CAnnoPduFactory::create`: Zoom's annotation message handler fails to check sender role or message origin, so it accepts AddObj annotation objects (0x10001) from any participant even in contexts meant to be restricted to acknowledgement-only messages (0x10002, differing from AddObj by a single opcode value) — letting an attacker's malformed drawing reach every other attendee in the meeting rather than being filtered. The protocol also routes annotation traffic over a direct, individually addressed channel per participant pair, letting an attacker target one specific victim from the sharer seat rather than broadcasting to the whole meeting.

A Security says it produced working exploits for the RCE-class bugs "in under a day, using fewer than 20 prompts" against publicly available frontier AI models. The workflow began with static analysis: researchers used IDA to disassemble the Android client (build v7.0.4, 121 native libraries) and built an AI-assisted static pre-ranker that scored every function reachable from a JNI entry point against dangerous-sink calls (memcpy/strcpy/sprintf-style copies, computed-size allocators), weighted by CWE severity, function size, and call depth — producing a ranked queue of 3,762 functions across 70 libraries. `libannotate.so` ranked only 45th on that static list; the team pivoted to dynamic tracing with Frida (referred to in A Security's writeup as "Frida MCP") once static ranking alone proved unproductive, exercising each meeting feature live while monitoring library loads and function invocations, which surfaced the annotation feature as the highest-value, protocol-reachable target despite its low static rank. Subsequent AI prompts reverse-engineered the proprietary annotation opcode set by mapping serialize/deserialize function pairs, audited the deserialization routines for memory-safety bugs, helped construct PDU payloads that traversed normal parsing paths, and identified the control-flow-hijack gadgets used on each target architecture. The firm frames the result as evidence that a capability class "previously only available to nation-state threat actors" now has a same-day production barrier; lead researcher Idan Levcovich (credited for CVE-2026-53413/53414) is quoted stating "the barrier to building this class of exploit has collapsed, and it will not come back."

A Security's writeup is explicit about what an attacker inherits once code is running inside the vulnerable process: "Code running inside these applications inherits their permissions, which in a conferencing client means camera, microphone and screen recording," and separately, "Once the nefarious code is running on the victim's device, the threat actor can quietly steal personal data, switch on the microphone or camera to spy on the target, or install other malicious software." The researchers also stress the one-to-many exposure of a single crafted message inside a call: "In a large call, that's a room full of targets from a single message, with no safe seat in it." On the detection side, A Security recommends alerting on a meeting client spawning an unrelated interpreter or browser process — "A meeting client has no reason to launch a browser, a shell or a script interpreter, so block it where you can and alert on it everywhere; our exploit made zoom.us open Safari." None of this — data theft, live audio/video capture, or additional malware installation — was demonstrated beyond the Safari-launch proof-of-concept; A Security frames it as the capability class the RCE unlocks given the OS-level permissions Zoom clients typically hold, not an observed payload.

Zoom rates the bugs High (CVSS 8.3 max) rather than Critical, a gap Zoom and reporters attribute to CVSS requiring User Interaction (UI:R) in the vector for the RCE-class CVEs — i.e., the victim must be in a meeting state where their client is set to receive/render annotation data — while A Security markets the class as "zero-click" because no explicit click or approval is needed beyond that meeting state, and there is no visible cue to the victim that an attack occurred. Zoom's disclosed remediation timeline shows the client-side fix for the CVE-2026-53413/53414 exploit path landing in Zoom Workplace v7.1.0 on 2026-06-22 (about two weeks after the 2026-06-10 report), a server-side mitigation for endpoints that had not yet updated on 2026-07-15, and the CVE-2026-53415 client fix in v7.1.5 on 2026-07-20 — all roughly three weeks to two months ahead of the coordinated public disclosure on 2026-08-11/12. A Security's own remediation notes flag that the 2026-07-15 server-side mitigation depends on Zoom's servers being able to inspect meeting content to filter malformed annotation objects, so meetings running with end-to-end encryption enabled do not benefit from that interim server-side filter and remain exposed until every participant's client is patched. As of publication neither CISA's KEV catalog nor any reviewed source shows in-the-wild exploitation or public weaponized exploit code; A Security's writeup gives exploit construction detail (opcode, buffer sizes, gadget, register planting, heap-spray object sizing) but not a drop-in tool.

MITRE ATT&CK techniques used in TL-2026-2001

Collection

T1005 Data from Local System; T1113 Screen Capture; T1123 Audio Capture; T1125 Video Capture

Execution

T1106 Native API; T1203 Exploitation for Client Execution

Impact

T1499.004 Endpoint Denial of Service: Application or System Exploitation

Resource Development

T1587.004 Develop Capabilities: Exploits; T1588.002 Obtain Capabilities: Tool; T1588.007 Obtain Capabilities: Artificial Intelligence

Affected products and versions in "Zoomsday" Flaws (CVE-2026-53413, CVE-2026-53414

  • Zoom Communications — Zoom Workplace
    Vulnerable versions: before 7.1.5 (all platforms); before 7.0.6 (LTS branch)
    Fixed in: 7.1.5; 7.0.6
  • Zoom Communications — Zoom Workplace VDI Client for Windows
    Vulnerable versions: before 7.0.11; before 6.6.16
    Fixed in: 7.0.11; 6.6.16
  • Zoom Communications — Zoom Rooms
    Vulnerable versions: before 7.1.5 (all platforms); before 7.1.0 per ZSB-26015
    Fixed in: 7.1.5
  • Zoom Communications — Zoom Meeting SDK
    Vulnerable versions: before 7.1.5 (all platforms); before 7.1.0 per ZSB-26015
    Fixed in: 7.1.5

Remediation for "Zoomsday" Flaws (CVE-2026-53413, CVE-2026-53414

Patches

  • Zoom Workplace 7.1.5 / 7.0.6
  • Zoom Workplace VDI Client for Windows 7.0.11 / 6.6.16
  • Zoom Rooms 7.1.5
  • Zoom Meeting SDK 7.1.5

Immediate actions

  • Update all Zoom Workplace clients (desktop and mobile, every platform) to v7.1.5, or the v7.0.6 LTS build
  • Update Zoom Rooms deployments and any application embedding the Zoom Meeting SDK to v7.1.5
  • Update Zoom Workplace VDI Client for Windows to v7.0.11, or the v6.6.16 LTS build
  • Confirm exposure to Zoom's server-side annotation-origin-validation mitigation (deployed 2026-07-15) for any fleet endpoints that cannot be patched immediately

Workarounds

  • Disable or restrict meeting annotation/whiteboard permissions for participants on clients that cannot yet be updated
  • Avoid enabling annotation in meetings that include external or untrusted participants until all attendee clients are confirmed patched
  • Be aware that Zoom's 2026-07-15 server-side mitigation cannot inspect or filter malicious annotation objects in end-to-end-encrypted meetings; unpatched clients in E2EE meetings remain fully exposed regardless of the server-side fix

Longer-term hardening

  • Enforce Zoom client auto-update policy via MDM/endpoint management so clients do not drift onto unpatched builds
  • Include third-party conferencing/collaboration clients (Zoom, Teams, Webex, etc.) in routine vulnerability and asset-inventory scanning rather than limiting coverage to OS and browser software
  • Subscribe to and triage Zoom's ZSB security-bulletin feed the same way OS vendor advisories are tracked
  • Evaluate whether meeting annotation/whiteboard needs to be enabled by default org-wide, given it is now a demonstrated cross-participant attack surface

CVEs associated with "Zoomsday" Flaws (CVE-2026-53413, CVE-2026-53414

CVE-2026-53413, CVE-2026-53414, CVE-2026-53415

Weaknesses (CWE) in "Zoomsday" Flaws (CVE-2026-53413, CVE-2026-53414

CWE-787, CWE-126, CWE-416

Timeline of "Zoomsday" Flaws (CVE-2026-53413, CVE-2026-53414

  • A Security discovers the annotation memory-corruption vulnerability while dynamically tracing the Zoom Android client (v7.0.4) with Frida after an AI-assisted static analysis pass across 3,762 functions in 70 native libraries ranked it only 45th.
  • A Security confirms zero-click remote code execution primitives across multiple client platforms (macOS arm64 via a shared-cache execvp gadget; Android via ExtChild heap spray and vtable corruption).
  • A Security reports the vulnerability cluster to Zoom.
  • Zoom acknowledges receipt of the vulnerability report.
  • Zoom deploys a client-side fix (Zoom Workplace v7.1.0) addressing the CVE-2026-53413/CVE-2026-53414 exploit path.
  • Zoom deploys a server-side mitigation to protect endpoints still running earlier, unpatched client versions; the mitigation cannot inspect or filter malicious annotation objects in end-to-end-encrypted meetings.
  • Zoom ships the client-side fix for CVE-2026-53415 (use-after-free in CAnnoObjAutoMetaShape) in Zoom Workplace v7.1.5.
  • Zoom publishes security bulletins ZSB-26015, ZSB-26016, and ZSB-26017; CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415 are assigned; A Security publishes its "Zoomsday" technical writeup crediting Idan Levcovich and Lidor Elias.
  • Malwarebytes, The Hacker News, SecurityWeek, Security Affairs, and other outlets report publicly on the Zoomsday flaws.

Sources cited for "Zoomsday" Flaws (CVE-2026-53413, CVE-2026-53414

Detection coverage for TL-2026-2001

As of 2026-08-12, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2001 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
15 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats