ZscalerCVE-2026-59568
Zscaler Client Connector: remote code execution
Critical9.1CVE-2026-59568 · Published Aug 24, 2026 · updated Aug 28, 2026
Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Client Connector Product | < Windows: 4.6.0.457, 4.7.0.317, 4.8.0.232, 4.9.0.372 | Windows: 4.6.0.457, 4.7.0.317, 4.8.0.232, 4.9.0.372 |
| < MacOS: 4.5.2.312, 4.7.0.292, 4.8.0.191 | MacOS: 4.5.2.312, 4.7.0.292, 4.8.0.191 | |
| < Linux: 3.7.2.64, 4.2.1.64 | Linux: 3.7.2.64, 4.2.1.64 | |
| < Android: 4.2 | Android: 4.2 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-20
More Zscaler advisories
All Zscaler| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 14 | Zscaler Client Connector: improper input validation | High7.5 | Android: 4.2.0.152+1 more |
| Sep 14 | Zscaler Client Connector: race condition | High8.1 | 4.6.0.486+3 more |
| Aug 24 | Zscaler Client Connector: privilege escalation | High8.8 | Windows: 4.6.0.457+8 more |
| Aug 24 | Zscaler Client Connector: authentication bypass | Critical9.1 | Windows: 4.6.0.457+7 more |
| Aug 24 | Zscaler Client Connector: buffer overflow | High8.8 | Windows: 4.6.0.457+3 more |
| Aug 24 | Zscaler Client Connector: buffer overflow | High8.4 | Android: 4.2+1 more |