Zoom Patches “Zoomsday” Zero-Click Flaw Enabling Remote Code Execution
Zoom patched CVE-2026-53413, a zero-click annotation flaw dubbed "Zoomsday" allowing remote code execution on meeting participants' devices across all platforms.
Zoom patched four vulnerabilities, including CVE-2026-53413, a stack buffer overflow in CAnnoFormatBlock::Deserialize in the annotation protocol that allows zero-click remote code execution on another participant's device. A Security also found CVE-2026-53414, a buffer overread enabling denial-of-service crashes, and CVE-2026-53415, a use-after-free Zoom had already discovered internally. Updates shipped for Workplace 7.1.5 and 7.0.6, Rooms 7.1.5, and Meeting SDK 7.1.5 across all supported platforms.
Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client
A Security researchers disclosed three Zoom annotation flaws enabling zero-click client hijacking; Zoom shipped fixes in June and July with no exploitation reported.
Researchers at A Security found three flaws in Zoom's annotation feature: CVE-2026-53413 (CVSS 8.3, buffer over-write), CVE-2026-53414 (CVSS 6.5, buffer over-read), and CVE-2026-53415 (CVSS 8.3, use-after-free). A crafted drawing object sent over the wrong message channel can overwrite adjacent memory and hijack another attendee's client with no user interaction. Fixes shipped in Zoom Workplace 7.1.5/7.0.6, VDI Client 7.0.11/6.6.16, and Zoom Rooms/Meeting SDK 7.1.0+ during June and July. No exploitation has been reported and the flaws are absent from CISA's Known Exploited Vulnerabilities catalog.
Researchers found a way to hijack devices through Zoom screen sharing
Researchers used a public AI tool to find a Zoom flaw enabling device hijacking via screen sharing in under 20 prompts.
Security researchers discovered a serious vulnerability in Zoom that can be used to hijack devices through the screen-sharing feature. The flaw was reportedly found by a publicly available AI tool in fewer than 20 prompts, highlighting the role of agentic AI in vulnerability discovery. The article does not report active exploitation or assign a CVE in the provided text.
Flock cameras are riddled with security vulnerabilities and hardcoded creds
Leaked Flock ALPR camera firmware reveals EOL Android 8.1, a 2017 Linux kernel, and hardcoded API keys granting access to production credentials.
DDoSecrets published filesystem images from an in-use Flock ALPR camera, obtained by the hacker collective stegan0gram and investigated by 404 Media and Wired. Micah Lee's analysis shows the camera runs Android 8.1 with a security patch level of 2018-06-05 and Linux kernel 3.18.71, missing roughly eight years of Android fixes. The firmware exposes a hardcoded API key for Flock's hpnotiq backend that can retrieve Auth0 client credentials for any camera by MAC address, with credentials stored in plaintext. Likely unpatched flaws include CVE-2021-1905 (Qualcomm Adreno use-after-free) and CVE-2018-9568 (WrongZone kernel socket type confusion); Flock says it received no reports via its disclosure policy.