Skip to content
ZscalerCVE-2026-59564

Zscaler Client Connector: authentication bypass

Critical9.1CVE-2026-59564 · Published Aug 24, 2026 · updated Aug 28, 2026

An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and the Zscaler Client Connector Portal.

Zscaler advisory

Affected versions

PackageAffectedFixed in
Client Connector
Product
< Windows: 4.6.0.457, 4.7.0.317, 4.8.0.232, 4.9.0.372Windows: 4.6.0.457, 4.7.0.317, 4.8.0.232, 4.9.0.372
< MacOS: 4.5.2.312, 4.7.0.292, 4.8.0.191MacOS: 4.5.2.312, 4.7.0.292, 4.8.0.191
< iOS: 4.5.1iOS: 4.5.1
< Android: 4.2Android: 4.2
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-304

More Zscaler advisories

All Zscaler
Advisory
Zscaler Client Connector: improper input validation
High7.5Sep 14
Zscaler Client Connector: race condition
High8.1Sep 14
Zscaler Client Connector: privilege escalation
High8.8Aug 24
Zscaler Client Connector: remote code execution
Critical9.1Aug 24
Zscaler Client Connector: buffer overflow
High8.8Aug 24
Zscaler Client Connector: buffer overflow
High8.4Aug 24

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.