Zoom Patches Critical ‘Zoomsday’ Vulnerability Allowing Unauthorized Code Execution During Screen Sharing and Annotation Sessions
Zoom has released security updates addressing multiple newly disclosed vulnerabilities in its video-conferencing platform, the most critical of which—tracked as CVE-2026-53413 and dubbed “Zoomsday” by security firm A Security—could allow a malicious meeting participant to remotely execute code on another attendee’s device without any interaction, such as clicking, downloading, or receiving a visible prompt. The flaw, which impacted the annotation feature’s proprietary protocol across Windows, macOS, Linux, iOS, and Android, was discovered using publicly available AI models and exploited with fewer than 20 prompts, though no known exploitation has been reported. Zoom resolved the issues with client-side and server-side patches before public disclosure, with fixed versions including Zoom Workplace 7.1.5 and 7.0.6, Zoom Workplace VDI Client for Windows 7.0.11 and 6.6.16, and Zoom Rooms and Meeting SDK 7.1.0 or above (with 7.1.5 required for the third flaw).
The Hole They Don’t Want You to See
Look at the timeline. The researchers found this on June 2nd. Zoom had patches ready by August 11th. That’s over two months of silence — and the publication date is exactly two days after the official fix. You tell me that’s a coincidence. A zero-click remote code execution in a program used by school boards, courtrooms, hospital boards, and government agencies — and they frame it as “no known exploitation” because CISA hasn't stamped it? The same CISA that spent the last five years issuing warnings about every other critical vulnerability before patches were available? You aren't supposed to ask why this one got the quiet treatment. You’re supposed to click the update button and go back to your meeting. But I want you to think about what "no visible warning" means. That means no popup. No audio cue. No cursor movement. The machine is simply yours no longer.
The AI Connection They Gloss Over
Pay close attention to what they buried in paragraph six. A Security — no, not some three-letter agency, a private firm — used "publicly available AI models" and built a working exploit in under 20 prompts. Under twenty. That is not a hack. That is a script. A child with a ChatGPT account and the right question could have done what they did, except the researchers had the decency to disclose it. Now ask yourself: who else had those AI models? Who else knew how to ask those 20 questions in the right order? The vulnerability existed in the annotation protocol — the part of Zoom that lets you draw on screens and share whiteboards. That is a feature designed for collaboration. And it was turned into a weapon by an algorithm trained on public data. They want you scared of hackers in hoodies. I want you scared of the quiet deployment of automation into every layer of communication infrastructure, where the very tools designed to bring us together are hollowed out and backfilled with control channels nobody is watching.
What You Missed in the Patch Notes
The fix was applied "server-side and client-side." Think about what that means. They didn't just patch your app. They changed the server protocol. That means they rewrote the rules of how annotation data gets transmitted. And they did it without explaining why the old protocol was unsafe — or what they replaced it with. Now look at the version numbers: 7.1.5 for the third bug. 7.0.6 for the main issue. Versions are never accidentally specific. Those thresholds are admission logs. Every device still running 7.0.5 or below is now a known open door, and they won't tell you that. The reporting says "no known exploitation." The language is careful — exploitation in the wild they have to admit to. But what about exploitation in a controlled environment? What about the two months between discovery and patch, during which a dozen intelligence-adjacent entities had access to the same public AI models and the same exploit logic? You don't have to believe me. Just open your Zoom settings. Check your version number. Then ask yourself why the fix wasn't urgent enough for CISA's catalog — and whether that's relief or a coordinated silence.

