Israeli cybersecurity firm A Security has disclosed a set of Zoom vulnerabilities that could allow a malicious meeting participant to execute code on another attendee's device without requiring the victim to click a link, download a file, or approve an action. The attack, named Zoomsday, targeted Zoom's annotation system and was built with the help of publicly available AI models in under 24 hours.
According to A Security, a researcher used fewer than 20 AI prompts to discover the flaws and develop a working exploit. The vulnerabilities are tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415. The two high-severity issues, CVE-2026-53413 and CVE-2026-53415, received CVSS scores of 8.3, while CVE-2026-53414 was rated medium severity. The flaws affected Zoom applications on Windows, macOS, Linux, Android, and iOS, and could be triggered from either side of a call. A compromised presenter could attack participants, or a participant could target the presenter. Once exploited, attackers could steal personal information, install malware, or activate the device's microphone and camera with no visible warning to the victim.
Zoom released fixes between June 22 and July 20 and advises affected Workplace users to upgrade to version 7.1.5 or 7.0.6, depending on their branch. Older Zoom Rooms and Meeting SDK releases are also affected. However, A Security warned that server-side protections cannot fully block the attack in end-to-end encrypted meetings because Zoom cannot inspect encrypted traffic. Users running older vulnerable clients therefore remain exposed.
The disclosure is particularly relevant to the cryptocurrency industry. Threat actors have repeatedly used Zoom calls and compromised Telegram accounts to target crypto founders, developers, investors, and executives. THORChain co-founder JP Thor lost approximately $1.3 million in September 2025 after joining what appeared to be a legitimate Zoom meeting. A December 2025 report detailed a $300 million campaign by North Korean-linked hackers using fake Zoom or Microsoft Teams meetings and deepfake footage to install remote-access malware. Former Animoca Brands executive Mehdi Farooq reported losing a large portion of his life savings in a similar attack in June 2025, and Manta Network co-founder Kenny Li reported an attempted Zoom attack in April 2025.
A Security noted that the Zoomsday exploit removes a major hurdle from those earlier attacks: successful compromise no longer depends on persuading a crypto holder to install software or accept a fake update. Simply being in the same meeting with a vulnerable client could provide an attack path. The firm warned that exploits of this type are treated as weapons and can be sold for millions, while the speed of discovery underscores how AI is accelerating vulnerability research. Mozilla previously found 271 vulnerabilities in Firefox during testing of Anthropic's Claude Mythos, showing that AI can examine large codebases faster than manual review.
Zoom's July security bulletins also included CVE-2026-53412, a critical improper input validation vulnerability in Zoom Workplace for Windows that could allow an unauthenticated attacker to carry out an account takeover through network access.