Zoom Communications Vulnerabilities and Affected Products
Vulnerabilities associated with Zoom Clients.
Products
Clear product- Zoom Clients4 vulnerabilities
- Zoom Workplace4 vulnerabilities
- Zoom Rooms2 vulnerabilities
- Zoom Workplace VDI Plugin2 vulnerabilities
- Remote Control for Zoom Contact Center1 vulnerability
- Zoom VDI1 vulnerability
- Zoom Workplace for Windows1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-53415HIGH | Zoom Clients - Use After FreeUse after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve remote code execution of another participant via network access. CWE-416Aug 11, 2026 | CVSS8.3v3.1 | EPSS0.388% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-53414MEDIUM | Zoom Clients - Buffer Over-readMissing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting participant to conduct a denial of service on another participant via network access. CWE-126Aug 11, 2026 | CVSS6.5v3.1 | EPSS0.276% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-53413HIGH | Zoom Clients - Buffer Over-writeMissing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting participant to achieve remote code execution of another participant via network access. CWE-787Aug 11, 2026 | CVSS8.3v3.1 | EPSS0.409% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-53410HIGH | Zoom Clients for Windows - Race ConditionA time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to escalate privileges. CWE-367Jul 16, 2026 | CVSS7.0v3.1 | EPSS0.094% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |