CVE-2026-59570
- EPSS 0.09%
- Veröffentlicht 14.09.2026 14:47:13
- Zuletzt bearbeitet 18.09.2026 19:08:02
On affected versions of Zscaler client connector, a pre-installed peer app can tear down the Zscaler tunnel, force user logout, and toggle packet capture.
CVE-2026-59569
- EPSS 0.12%
- Veröffentlicht 14.09.2026 14:42:34
- Zuletzt bearbeitet 18.09.2026 19:08:02
An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allows an attacker to potentially bypass Zscaler controls.
CVE-2026-25687
- EPSS 0.23%
- Veröffentlicht 14.09.2026 14:37:04
- Zuletzt bearbeitet 18.09.2026 19:08:02
A race condition in the ZPA tunnel handler of affected versions of Zscaler Client Connector (ZCC) allows a heap corruption, resulting in a denial of service (client crash) and potentially arbitrary code execution in the context of the ZCC process.
CVE-2026-59568
- EPSS 0.38%
- Veröffentlicht 24.08.2026 13:44:21
- Zuletzt bearbeitet 28.08.2026 18:39:48
Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context.
CVE-2026-59567
- EPSS 0.1%
- Veröffentlicht 24.08.2026 13:41:38
- Zuletzt bearbeitet 28.08.2026 18:39:48
Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving an unprivileged user the ability to execute arbitrary code in a privileged context.
CVE-2026-59566
- EPSS 0.12%
- Veröffentlicht 24.08.2026 13:41:04
- Zuletzt bearbeitet 28.08.2026 18:39:48
A locally exploitable buffer overflow bug can cause a local denial-of-service attack on affected versions of Zscaler Client Connector on Android and ChromeOS.
CVE-2026-59565
- EPSS 0.27%
- Veröffentlicht 24.08.2026 13:40:23
- Zuletzt bearbeitet 28.08.2026 18:39:48
A remotely exploitable buffer overflow bug can cause a local and kernel denial-of-service attack on affected versions of Zscaler Client Connector on Windows.
CVE-2026-59564
- EPSS 0.3%
- Veröffentlicht 24.08.2026 13:39:16
- Zuletzt bearbeitet 28.08.2026 18:39:48
An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and the Zscaler Client Connector Portal.
CVE-2026-22569
- EPSS 0.18%
- Veröffentlicht 31.03.2026 14:54:57
- Zuletzt bearbeitet 24.07.2026 20:10:00
An incorrect startup configuration of affected versions of Zscaler Client Connector on Windows may cause a limited amount of traffic from being inspected under rare circumstances.
CVE-2025-54983
- EPSS 0.12%
- Veröffentlicht 12.11.2025 03:07:39
- Zuletzt bearbeitet 15.04.2026 00:35:42
A health check port on Zscaler Client Connector on Windows, versions 4.6 < 4.6.0.216 and 4.7 < 4.7.0.47, which under specific circumstances was not released after use, allowed traffic to potentially bypass ZCC forwarding controls.