Update Zoom. The most serious flaws disclosed in August 2026 can let a malicious meeting participant run code on another participant’s device, and the MS-ISAC says exploitation may require no action from the target. The fixed version depends on the Zoom product and release branch: check the version thresholds below rather than assuming one update number covers every app, room, VDI deployment, or SDK.
What is the Zoom security risk?
The August 2026 “Zoomsday” vulnerabilities affect Zoom client software. The MS-ISAC advisory issued August 12, 2026, says a malicious meeting participant could exploit a missing bounds check in the annotator function to take control of another participant’s device without user interaction. Successful exploitation could allow data theft, camera or microphone activation, or malware installation. These are possible consequences, not evidence that every affected meeting or device has been compromised.
The Cyber Security Agency of Singapore (CSA) describes four CVEs in the August group. Two are rated CVSS v3.1 8.3 and involve potential remote code execution; the other two cover denial of service and information disclosure. CVSS scores indicate assessed severity, not whether an attack has occurred.
| CVE | Issue and reported impact | CVSS v3.1 |
|---|---|---|
| CVE-2026-53413 | Missing bounds check in the annotator function; a meeting participant may achieve remote code execution on another participant through network access. | 8.3 (CSA, 2026) |
| CVE-2026-53414 | Missing bounds check causing a buffer over-read and potential denial of service. | 6.5 (CSA, 2026) |
| CVE-2026-53415 | Use-after-free in the annotator function with potential remote code execution. | 8.3 (CSA, 2026) |
| CVE-2026-53416 | Path traversal in Zoom VDI Client and plugins, potentially exposing information through local access. | 7.1 (CSA, 2026) |
MS-ISAC reported no evidence of exploitation in the wild as of its August 12 advisory. That is a time-bound status, not a guarantee that the flaws cannot be exploited or that the status has not changed since.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minute#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Which Zoom versions need an update?
MS-ISAC lists the following affected releases for the August vulnerabilities. The “before” versions are the relevant thresholds: install a fixed release at or above the threshold for the product and branch you actually use. Do not use the Workplace cutoff to assess Rooms, VDI, or SDK installations.
| Product or component | Affected versions reported by MS-ISAC | Practical update check |
|---|---|---|
| Zoom Workplace on supported platforms | Before 7.1.5 or before 7.0.6, in the respective branches. | Use 7.1.5 or later on the 7.1 branch, or 7.0.6 or later on the 7.0 branch. |
| Zoom Workplace VDI Client for Windows | Before 7.0.11 or before 6.6.16. | Check which listed branch is deployed and update to its threshold or later. |
| Zoom Rooms | Before 7.1.0. | Update to 7.1.0 or later. |
| Zoom Meeting SDK | Before 7.1.0. | Update the SDK-dependent deployment to 7.1.0 or later. |
| Zoom Video SDK | CSA says versions before 2.6.0 or 2.6.5 are affected, depending on the CVE. | Identify the applicable CVE and SDK branch before deciding which threshold applies. |
| Zoom VDI plugins (CVE-2026-53416) | Before 7.0.11 or before 6.6.15. | Check the plugin version separately from the VDI Client; use the matching branch threshold. |
The advisory information does not map the two Video SDK thresholds to specific CVEs in the material available here. If you manage a Video SDK deployment, confirm the applicable fixed release against the vendor’s advisory for that CVE rather than choosing a threshold by guesswork.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Do Mac users need to update Zoom?
Yes. MS-ISAC includes Zoom Workplace on supported platforms in the August vulnerability scope, so macOS users should check their installed branch against the Workplace thresholds above and update through Zoom’s official release channel. The advisory’s summary does not enumerate every supported operating system, so it should not be read as a full platform-by-platform affected-version matrix.
Zoom’s security-bulletin index also listed a separate medium-severity Zoom Rooms for macOS issue, CVE-2025-67461, among earlier advisories. The available bulletin summary does not state its affected or fixed version threshold; do not infer one from the August client cutoffs.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteRank #3
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
What other 2026 Zoom advisories affect Windows?
The August cross-platform client flaws are not the only 2026 Zoom security notices relevant to Windows. Canada’s Cyber Centre recorded March 10, 2026 advisories for these earlier affected releases:
- Zoom Meeting SDK for Windows before 6.6.11.
- Zoom Rooms for Windows before 6.6.5.
- Zoom Workplace for Windows before 6.6.11.
- Zoom Workplace VDI Client for Windows before 6.4.17, 6.5.15, and 6.6.10.
Separately, Zoom’s bulletin index on July 14, 2026 listed a critical Zoom Workplace for Windows issue, CVE-2026-53412, and high-severity Windows issues affecting Zoom Clients, Zoom Rooms, and the VDI Plugin. The index summary cited here does not give their fixed version numbers or technical details, so the August thresholds should not be assumed to resolve those separate advisories. Review the vendor’s bulletin for the component and CVE involved.
Quick Recap
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
How should you update and verify Zoom?
- Inventory the deployment. Identify whether each endpoint runs Zoom Workplace, Zoom Rooms, a VDI Client or plugin, or software built with a Zoom SDK. Record the operating system and installed version; in managed environments, include meeting-room systems and virtual desktop images.
- Match version to branch. Compare each version with the corresponding product threshold in the table. A version number for Workplace does not establish that a Rooms endpoint, VDI plugin, or SDK-based application is fixed.
- Install from an official release channel. Update the relevant application, component, or SDK-dependent deployment. For SDKs embedded in another product, coordinate the update with the team that builds or distributes that software.
- Verify deployment. Recheck installed versions after rollout and use vulnerability scanning or application patch-management reporting to find endpoints that missed the update. Validate rooms and VDI endpoints individually or through their management systems.
- Address any delay as temporary risk reduction. MS-ISAC recommends prompt vendor updates, automated patch management, and vulnerability scanning. If immediate patching is not possible, limit untrusted meeting participation and apply least-privilege and network-segmentation controls while remediation is scheduled. These measures reduce exposure; they do not replace installing the fix.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

