This is why full disclosure is so effective. Nothing else works quite like dropping a full PoC and details of an exploit publicly to light a fire under their ass to fix it.
But responsible disclosure absolutely does not mean “no disclosure”. It means give them a chance to fix it. If they choose not to you disclose so that people know that they need to take steps to protect themselves.
The important thing is that the disclosure must become public. It doesn’t matter that they pushed an update, as none of the victims who had deleted/“uninstalled” zoom will get the update, and without the update they’ll still be running the server.
The only way anyone would know about it is with the details being public.
I’m waiting for Apple to use xprotect to kill the server on all machines, as that’s the only true solution for the uninstalled victims