Skip to content
ZscalerCVE-2026-59568

Zscaler Client Connector: remote code execution

Critical9.1CVE-2026-59568 · Published Aug 24, 2026 · updated Aug 28, 2026

Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context.

Zscaler advisory

Affected versions

PackageAffectedFixed in
Client Connector
Product
< Windows: 4.6.0.457, 4.7.0.317, 4.8.0.232, 4.9.0.372Windows: 4.6.0.457, 4.7.0.317, 4.8.0.232, 4.9.0.372
< MacOS: 4.5.2.312, 4.7.0.292, 4.8.0.191MacOS: 4.5.2.312, 4.7.0.292, 4.8.0.191
< Linux: 3.7.2.64, 4.2.1.64Linux: 3.7.2.64, 4.2.1.64
< Android: 4.2Android: 4.2
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-20

More Zscaler advisories

All Zscaler
Advisory
Zscaler Client Connector: improper input validation
High7.5Sep 14
Zscaler Client Connector: race condition
High8.1Sep 14
Zscaler Client Connector: privilege escalation
High8.8Aug 24
Zscaler Client Connector: authentication bypass
Critical9.1Aug 24
Zscaler Client Connector: buffer overflow
High8.8Aug 24
Zscaler Client Connector: buffer overflow
High8.4Aug 24

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.