PatchSiren

Zscaler CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Zscaler CVE published 2026-09-14

CVE-2026-59570

A pre-installed peer app can tear down the Zscaler tunnel, force user logout, and toggle packet capture on affected Zscaler client connector versions. This issue affects defenders and administrators using Zscaler client connector, who should verify versions and configurations to prevent unauthorized tunnel teardown and user logout. The CVE record and NVD entry provide limited information on affected versi [truncated]

HIGH Zscaler CVE published 2026-09-14

CVE-2026-59569

A high-severity improper input validation vulnerability exists in Zscaler Client Connector on Android and ChromeOS, potentially allowing attackers to bypass Zscaler controls. Defenders should assess exposure, particularly for those using Zscaler Client Connector on Android and ChromeOS, and prioritize verification of affected versions and remediation.

HIGH Zscaler CVE published 2026-09-14

CVE-2026-25687

A race condition in the ZPA tunnel handler of affected versions of Zscaler Client Connector (ZCC) allows a heap corruption, resulting in a denial of service (client crash) and potentially arbitrary code execution in the context of the ZCC process. This vulnerability is particularly concerning for defenders responsible for Zscaler Client Connector deployments, as it could lead to significant disruptions in [truncated]

MEDIUM Zscaler CVE published 2026-04-02

CVE-2026-22569

The Zscaler Client Connector versions 4.7 and 4.8 on Microsoft Windows contain a vulnerability where a domain is misspelled and added to an internal bypass list by default. This could lead to a limited amount of traffic not being inspected under specific circumstances. The issue was fixed in versions 4.7.0.141 and 4.8.0.63. According to the CVSS score of 6.5, the severity is classified as MEDIUM. The vuln [truncated]