
Researchers have discovered three security vulnerabilities in Zoom’s Annotation feature—the tool that allows participants to draw on a shared screen. Zoom has already released patches.
Key Points:
• A malformed drawing could execute code on a viewer’s machine or inversely on the screen sharer’s computer.
• Zoom assigned CVE-2026-53413 and CVE-2026-53415 with a high severity rating of 8.3.
• Patches have been released since June and July—users who have not updated remain exposed.
• To date, there are no reports of actual attacks in the wild.
[Insight: Video conferencing software isn’t just about cameras—it’s a gateway to your computer. Open Zoom and click “Check for Updates” today, because an uninstalled patch is as good as no patch at all.]
Kun Long
Author at The Sharing KH