nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-53413 CVE-2026-53413
HIGH
Zoom Clients - Buffer Over-write
Record summary
CVE-2026-53413 has a selected CVSS score of 8.3 (high); EIP currently links 1 repository PoC.
Description
Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting participant to achieve remote code execution of another participant via network access.
Description source: CVE List
Exploitation context
Available material
- Repository PoCs
- 1
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 11, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Zoom ClientsBrowse Zoom Communications / Zoom ClientsDefault status: unaffected | CVE List | see references | affected |
Proofs of concept
1Repository PoCs
GitHubHORKimhab/CVE-2026-68820Repository PoCby HORKimhabStars: 1Not analyzed3 files
References
2zoom.com
https://www.zoom.com/en/trust/security-bulletin/zsb-26015