PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-59570 Zscaler CVE debrief

A pre-installed peer app can tear down the Zscaler tunnel, force user logout, and toggle packet capture on affected Zscaler client connector versions. This issue affects defenders and administrators using Zscaler client connector, who should verify versions and configurations to prevent unauthorized tunnel teardown and user logout. The CVE record and NVD entry provide limited information on affected versions and remediation, requiring further verification. The vulnerability allows a pre-installed peer app to disrupt the Zscaler tunnel, potentially leading to unauthorized access or data breaches if not properly addressed.

Vendor
Zscaler
Product
Client Connector
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-14
Original CVE updated
2026-09-18
Advisory published
2026-09-14
Advisory updated
2026-09-18

Who should care

Defenders and administrators using Zscaler client connector should verify versions and configurations to prevent unauthorized tunnel teardown and user logout.

Why it matters

CVE-2026-59570 affects Zscaler client connector, allowing a pre-installed peer app to tear down the Zscaler tunnel, force user logout, and toggle packet capture. Defenders and administrators should verify versions and configurations to prevent unauthorized tunnel teardown and user logout.

  • Verify Zscaler client connector versions and configurations to prevent unauthorized tunnel teardown
  • Monitor for unauthorized user logout and packet capture
  • Review and update incident response plans to address potential tunnel teardown and user logout

Technical summary

CVE-2026-59570 affects Zscaler client connector, allowing a pre-installed peer app to tear down the Zscaler tunnel, force user logout, and toggle packet capture. The vulnerability is considered high severity, with a CVSS score of 7.5. Defenders and administrators should verify Zscaler client connector versions and configurations to prevent unauthorized tunnel teardown and user logout. The issue can be addressed by reviewing and updating incident response plans to address potential tunnel teardown and user logout.

Defensive priority

Verify Zscaler client connector versions and configurations to prevent unauthorized tunnel teardown and user logout.

Recommended defensive actions

  • Verify Zscaler client connector versions and configurations
  • Monitor for unauthorized tunnel teardown and user logout
  • Review packet capture settings

Evidence notes

The CVE record and NVD entry provide limited information on affected versions and remediation. Further verification is required to determine the full scope of the vulnerability, including potentially affected versions, configurations, and potential mitigations. Defenders should review the official CVE record and NVD entry, and verify Zscaler client connector versions and configurations to prevent unauthorized tunnel teardown and user logout. Evidence from the CVE record and NVD entry,

Sources and references

Verified primary and authoritative sources

  • CVE-2026-59570 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-59570

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-59570 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-59570

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.