PatchSiren

Zscaler CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Zscaler CVE published 2026-04-02

CVE-2026-22569

The Zscaler Client Connector versions 4.7 and 4.8 on Microsoft Windows contain a vulnerability where a domain is misspelled and added to an internal bypass list by default. This could lead to a limited amount of traffic not being inspected under specific circumstances. The issue was fixed in versions 4.7.0.141 and 4.8.0.63. According to the CVSS score of 6.5, the severity is classified as MEDIUM. The vuln [truncated]