Skip to content
ZscalerCVE-2026-25684

Zscaler: improper input validation

Medium4.4CVE-2026-25684 · Published Sep 18, 2026

A file type attribution issue in Zscaler Internet Access File Type Control evaluation rules may allow improper evaluation of File Type Control policies in rare circumstances.

Zscaler advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-20

More Zscaler advisories

All Zscaler
Advisory
Zscaler Client Connector: improper input validation
High8.1Sep 14
Zscaler Client Connector: improper input validation
High7.5Sep 14
Zscaler Client Connector: race condition
High8.1Sep 14
Zscaler Client Connector: privilege escalation
High8.8Aug 24
Zscaler Client Connector: remote code execution
Critical9.1Aug 24
Zscaler Client Connector: authentication bypass
Critical9.1Aug 24

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.