Fetching from the wire…
Security2026-08-12 · source-backed
CVE-2026-53413/53414/53415, disclosed August 11, target screen-share annotation and let one meeting participant execute code on another's device with zero interaction. Lead bug rated 8.3 (Security Affairs). A Security says the working exploit took under a day and fewer than 20 prompts against publicly available models. That used to be nation-state time and budget. Patch to Zoom Workplace 7.1.5/7.0.6, Rooms 7.1.5, Meeting SDK 7.1.5.
Each link below shares sources, entities, or timing with this story.
Shared entities / Shared topic / Earlier coverage
Both cover CVE, RCE, Security; overlapping topics (code, prompt); earlier CVE coverage from 2026-04-03.
Shared entities / Earlier coverage / Tension
Both cover CVE, RCE, Security; earlier CVE coverage from 2026-03-23; pushes against this story (against).
Zoom partners with Salesforce / Shared entity: August / Earlier coverage
Linked by a graph relationship (Zoom partners with Salesforce); both cover August; earlier August coverage from 2026-08-09.
Linked by a graph relationship (Zoom partners with Salesforce); both cover August; earlier August coverage from 2026-04-21.
Canva partners with Zoom
Linked by a graph relationship (Canva partners with Zoom).
Linked by a graph relationship (Canva partners with Zoom).
Shared entities / Shared topic / Earlier coverage / Tension
Both cover CVE, RCE; overlapping topics (code, exploit); earlier CVE coverage from 2026-03-20.
Shared entities / Earlier coverage
Both cover August, RCE, Security; earlier August coverage from 2026-08-11.