PatchSiren cyber security CVE debrief
CVE-2026-59570 Zscaler CVE debrief
A pre-installed peer app can tear down the Zscaler tunnel, force user logout, and toggle packet capture on affected Zscaler client connector versions. This issue affects defenders and administrators using Zscaler client connector, who should verify versions and configurations to prevent unauthorized tunnel teardown and user logout. The CVE record and NVD entry provide limited information on affected versions and remediation, requiring further verification. The vulnerability allows a pre-installed peer app to disrupt the Zscaler tunnel, potentially leading to unauthorized access or data breaches if not properly addressed.
- Vendor
- Zscaler
- Product
- Client Connector
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-14
- Original CVE updated
- 2026-09-18
- Advisory published
- 2026-09-14
- Advisory updated
- 2026-09-18
Who should care
Defenders and administrators using Zscaler client connector should verify versions and configurations to prevent unauthorized tunnel teardown and user logout.
Why it matters
CVE-2026-59570 affects Zscaler client connector, allowing a pre-installed peer app to tear down the Zscaler tunnel, force user logout, and toggle packet capture. Defenders and administrators should verify versions and configurations to prevent unauthorized tunnel teardown and user logout.
- Verify Zscaler client connector versions and configurations to prevent unauthorized tunnel teardown
- Monitor for unauthorized user logout and packet capture
- Review and update incident response plans to address potential tunnel teardown and user logout
Technical summary
CVE-2026-59570 affects Zscaler client connector, allowing a pre-installed peer app to tear down the Zscaler tunnel, force user logout, and toggle packet capture. The vulnerability is considered high severity, with a CVSS score of 7.5. Defenders and administrators should verify Zscaler client connector versions and configurations to prevent unauthorized tunnel teardown and user logout. The issue can be addressed by reviewing and updating incident response plans to address potential tunnel teardown and user logout.
Defensive priority
Verify Zscaler client connector versions and configurations to prevent unauthorized tunnel teardown and user logout.
Recommended defensive actions
- Verify Zscaler client connector versions and configurations
- Monitor for unauthorized tunnel teardown and user logout
- Review packet capture settings
Evidence notes
The CVE record and NVD entry provide limited information on affected versions and remediation. Further verification is required to determine the full scope of the vulnerability, including potentially affected versions, configurations, and potential mitigations. Defenders should review the official CVE record and NVD entry, and verify Zscaler client connector versions and configurations to prevent unauthorized tunnel teardown and user logout. Evidence from the CVE record and NVD entry,
Sources and references
Verified primary and authoritative sources
-
CVE-2026-59570 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-59570
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-59570 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-59570
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.