Zoom Zoomsday Zero-Click Flaw: NC Small Business Alert

A zero-click Zoom flaw, CVE-2026-53413, lets anyone in a meeting take over a PC with no click. What NC small businesses patch now. Call (336) 886-3282.

Cover Image for Zoom Zoomsday Zero-Click Flaw: NC Small Business Alert

On August 11, 2026, Zoom patched a zero-click flaw, CVE-2026-53413, that lets one participant in a meeting run code on another participant's computer with no link to click, no file to open, and no prompt to accept. (SecurityWeek: Zoom Patches Zero-Click Code Execution Vulnerability) Researchers named it "Zoomsday," and the reason it matters to a High Point machine shop has nothing to do with your firewall or your servers. It has to do with the copy of Zoom on every laptop, and whoever you let into a meeting. (Security Affairs: Zoom Patches "Zoomsday" Zero-Click Flaw)

The uncomfortable part is that most small businesses cannot say, right now, which version of Zoom is running on their machines. That is the whole exposure. Finding those versions is a management job, and most shops have never assigned it to anyone.

Run Zoom for supplier calls, customer demos, or remote plant support anywhere in the Piedmont Triad? Ask Preferred Data Corporation to inventory your Zoom versions and get every machine current before someone tests this on you. We are in High Point, on-site within 200 miles, and we have kept North Carolina manufacturers patched since 1987. Call (336) 886-3282.

What is the Zoom Zoomsday flaw, in one plain sentence?

It lets anyone who shares a meeting with you take over your computer while you sit there watching, and you would see nothing. The bug lives in Zoom's annotation feature, the tool that lets people draw and add text on a shared screen. The short version: Zoom set aside a fixed 128-byte space for that annotation text but trusted a size sent over the network, so a crafted annotation writes past it and runs the attacker's code. (Security Affairs) You do not need the rest of the internals. You need to know it fires from inside a meeting.

Three facts make this worse than the average patch note. It is zero-click, meaning the victim does nothing and gets no warning. (SecurityWeek) It shipped alongside three siblings in the same August 11 disclosure, CVE-2026-53414, CVE-2026-53415, and CVE-2026-53416, so this was a cluster, not a one-off. And the fix is spread across a stack of separate version numbers, which is exactly why "we run Zoom" is not the same as "we are covered."

Key takeaway: The dangerous input is not an email or a download. It is a person in your meeting. So the question stops being whether the servers are patched and becomes who you let into the call, and how old their Zoom is.

Why does "we keep everything patched" not cover this?

Because the thing most small businesses patch well is the thing this attack ignores. Managed servers, the firewall, and Windows itself usually get patched on a schedule. The Zoom client on a salesperson's laptop updates when that salesperson happens to click "update," which for a lot of people is never. That gap is not hypothetical: exploitation of software vulnerabilities now sits behind roughly one in five breaches, up 34 percent in a single year, according to the Verizon 2025 Data Breach Investigations Report. (Infosecurity Magazine: Verizon DBIR Reveals 34% Jump in Vulnerability Exploitation) Unpatched desktop software is a large part of how attackers reach that number.

Zoom shows how fast the target moves. About four weeks before Zoomsday, on July 16, 2026, Zoom had already patched a separate critical Windows-only flaw, CVE-2026-53412, scored 9.8 out of 10, that let an unauthenticated attacker take over an account. (The Hacker News: Zoom Patches Critical Windows Flaw That Could Enable Account Takeover) (BleepingComputer: Zoom warns of critical account takeover vulnerability) Passing the July check does nothing for the August one. Two serious Zoom holes in under a month is the normal rhythm for any app this widely deployed, which is why a once-a-year "are we patched?" glance is worthless for desktop software.

Here is what actually closes Zoomsday, and notice it is a list of versions, not a single number:

Zoom productYou are safe on
Zoom Workplace (desktop and mobile)7.1.5 or 7.0.6
Zoom Rooms7.1.5
Meeting SDK7.1.5
Workplace VDI Client for Windows7.0.11 or 6.6.16
Workplace VDI Plugins7.0.11 or 6.6.15

Source: SecurityWeek. A shop that standardized on Zoom Rooms in its conference areas has a different job than one where forty people each installed Zoom themselves, and most Triad businesses are quietly the second kind.

Who can actually pull this off against your plant?

Anyone you invite, and anyone they forward the link to. The attack needs the target to be in a meeting with the attacker, which for a business that runs external calls is a low bar. A vendor demo, a prospect who asked for a screen-share, a recruiter, a "supplier" who turns out to be a lookalike account: any of them can be the participant who fires the annotation. The outsiders you screen the least, the ones you meet on a call once and never again, are the same people this bug would hand the keyboard to.

In the shops we manage, the machine most likely to be running a stale Zoom is not some engineer's laptop. It is the shared PC bolted to the conference-room TV, or the kiosk on the shop floor that nobody logs into for weeks, exactly the machines nobody updates because nobody's job says they have to. That conference-room box is also the one that joins every external supplier call. It is the worst possible machine to have three versions behind, and it is the one almost nobody checks.

Key takeaway: Your risk is not "does an employee click something." It is "who is allowed into the meeting, and how old is the Zoom on the machine they are looking at."

Already have an IT provider? Forward this and ask one question: what version of Zoom is on our conference-room and shop-floor machines right now? If they cannot answer today, that is the finding. Preferred Data managed IT treats endpoint app inventory as standing work. Call (336) 886-3282.

What should a Triad shop do about Zoom this week?

Get every Zoom install to a fixed version and stop relying on people to update themselves. There is no meaningful workaround for a zero-click memory bug; you update, or you stay exposed. Here is the order we work in, and it takes an afternoon, not a project:

  1. Find every copy of Zoom you own. Laptops, desktops, the conference-room PCs, Zoom Rooms appliances, and any VDI setup. The count is almost always higher than the owner guesses, because Zoom spreads by invitation.
  2. Push the fixed versions, do not ask for them. Move Workplace to 7.1.5 (or 7.0.6), Rooms to 7.1.5, and the VDI components to their fixed builds. If you run an RMM or Intune, that is a single deployment; if you do not, the Zoom MSI installer takes the version and settings on the command line, so one person can still reach every machine instead of walking desk to desk.
  3. Turn on automatic updates and lock them there. Zoom can update itself, and its IT admin settings let you force that on and stop users from switching it off, through the Zoom admin portal or the installer's auto-update switch. Set it once and the next Zoom flaw patches itself instead of becoming another manual scramble.
  4. Tighten who gets into meetings. Waiting rooms on, no joining before host, and a real rule about which outside parties get to share and annotate. Waiting rooms and host controls used to be about keeping a call tidy. Now they are what stands between a stranger and a machine on your network.
  5. Own the orphan machines. Assign the conference-room and shop-floor PCs to someone or to your IT provider, so the endpoints nobody logs into are still somebody's job.

For a business without in-house IT, steps one through three are same-day work. Preferred Data runs Zoom and other desktop-app patching as part of managed IT and monitoring across the Piedmont Triad, so the app your team lives in all day is not the one quietly three versions behind.

Is Zoom still safe to run after Zoomsday?

Yes, and swapping tools this week would be an overreaction that fixes nothing. Every major collaboration platform ships serious bugs; the ones worth staying on are the ones that patch fast and say so plainly, which Zoom did here. Blaming Zoom misses the point. The reason a fix dated August 11 might still not be on your conference-room PC is that the update was left to whoever happened to be sitting at it.

The contrarian point we make with owners in Greensboro and Charlotte: the app to worry about is not Zoom, which at least you know you run. It is the Teams call a customer makes you join, the Google Meet link a supplier sends, the meeting app on a foreman's personal phone that also dials into company calls. Zoomsday is a fixable problem on software you control. The tool nobody put on a list is the one that never gets patched, because nobody knows it is running. So do two things Monday: patch Zoom, and make someone write down every meeting app the company actually uses, because the next Zoomsday will land on the one you forgot.

Want a straight answer on whether your meeting tools are a liability or just a patch behind? Talk to Preferred Data Corporation, 1208 Eastchester Drive, Suite 131, High Point, NC 27265, or call (336) 886-3282. Local, manufacturing-focused, and answering the phone in North Carolina since 1987.

Frequently Asked Questions

Does the Zoom Zoomsday flaw mean our data was already stolen?

Not by itself. CVE-2026-53413 is a code-execution flaw that requires an attacker to share a meeting with the target and send a malicious annotation; there is no evidence every Zoom user was hit. But because it is zero-click and leaves no visible trace, you cannot rule out exposure on a machine that ran an old version during an external meeting. Update first, then decide whether any specific machine warrants a closer look.

Which Zoom version do we actually need?

For the main desktop and mobile app, Zoom Workplace 7.1.5 or 7.0.6 closes the flaw, per SecurityWeek. Zoom Rooms and the Meeting SDK need 7.1.5, and the Windows VDI client and plugins have their own fixed builds. Check the version inside Zoom under your profile, or have your IT provider report it across every machine at once.

We keep Windows and our servers patched. Are we not already protected?

No. Central patching usually covers the operating system and servers, but the Zoom desktop client updates on its own track, often left to each user. That is exactly the gap attackers use; the Verizon 2025 report put exploitation of vulnerabilities behind roughly one in five breaches, up 34 percent in a year. Desktop application patching has to be managed as deliberately as Windows Update.

Can we just tell everyone to update Zoom themselves?

You can ask, but relying on it is why this class of problem persists. On a managed fleet, the fix is to push the update centrally and enforce automatic updates so the next Zoom flaw is handled without a company-wide email. Self-service updating is how a conference-room PC ends up three versions behind.

Should a small manufacturer switch away from Zoom over this?

Almost never. Zoom disclosed the issue and shipped fixes across all its clients on August 11, 2026, which is the behavior you want from a vendor. The higher risk is the collaboration app your team adopted without IT knowing, because an unmanaged tool never gets patched at all. Manage what you have before you go shopping for something new.

How fast can Preferred Data get our machines current?

For most small businesses it is a same-day effort: inventory every Zoom install, push the fixed versions, and turn on enforced automatic updates. Multi-site operations across the Triad take a little longer only because each location's machines get checked. We price it off what you actually run, not a flat sticker.

References

  1. SecurityWeek. (2026, August). Zoom Patches Zero-Click Code Execution Vulnerability.
  2. Security Affairs. (2026, August). Zoom Patches "Zoomsday" Zero-Click Flaw Enabling Remote Code Execution.
  3. The Hacker News. (2026, July). Zoom Patches Critical Windows Flaw That Could Enable Account Takeover.
  4. BleepingComputer. (2026, July). Zoom warns of critical account takeover vulnerability.
  5. Infosecurity Magazine. (2025, April 23). Verizon's DBIR Reveals 34% Jump in Vulnerability Exploitation.
Support