ZscalerCVE-2026-25684
Zscaler: improper input validation
Medium4.4CVE-2026-25684 · Published Sep 18, 2026
A file type attribution issue in Zscaler Internet Access File Type Control evaluation rules may allow improper evaluation of File Type Control policies in rare circumstances.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-20
More Zscaler advisories
All Zscaler| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 14 | Zscaler Client Connector: improper input validation | High8.1 | Android: 4.2.0.152+1 more |
| Sep 14 | Zscaler Client Connector: improper input validation | High7.5 | Android: 4.2.0.152+1 more |
| Sep 14 | Zscaler Client Connector: race condition | High8.1 | 4.6.0.486+3 more |
| Aug 24 | Zscaler Client Connector: privilege escalation | High8.8 | Windows: 4.6.0.457+8 more |
| Aug 24 | Zscaler Client Connector: remote code execution | Critical9.1 | Windows: 4.6.0.457+8 more |
| Aug 24 | Zscaler Client Connector: authentication bypass | Critical9.1 | Windows: 4.6.0.457+7 more |