Zscaler Zscaler

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Zscaler product.

RSS Feeds for Zscaler security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Zscaler products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Zscaler Sorted by Most Security Vulnerabilities since 2018

Zscaler Client Connector40 vulnerabilities

Zscaler Proxy1 vulnerability

By the Year

In 2026 there have been 11 vulnerabilities in Zscaler with an average score of 7.5 out of ten. Last year, in 2025 Zscaler had 2 security vulnerabilities published. That is, 9 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 2.28.




Year Vulnerabilities Average Score
2026 11 7.48
2025 2 5.20
2024 11 7.43
2023 18 6.93
2022 0 0.00
2021 3 0.00

It may take a day or so for new Zscaler vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Zscaler Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-59563 Sep 28, 2026
Replay Attack on Zscaler MCP Server before v0.7.2 via Unbound HMAC Tokens Zscaler MCP Server versions 0.7.0 and 0.7.1 has an issue where HMAC confirmation tokens were not bound to the target resource identifier, allowing an MCP client or agent to replay a token generated for one resource to affect another resource of the same type. This issue is fixed in version 0.7.2.
CVE-2026-25684 Sep 18, 2026
Zscaler Internet Access File Type Control Policy Bypass A file type attribution issue in Zscaler Internet Access File Type Control evaluation rules may allow improper evaluation of File Type Control policies in rare circumstances.
CVE-2026-59570 Sep 14, 2026
Zscaler Client Connector: Peer App can tear down tunnel & force logout On affected versions of Zscaler client connector, a pre-installed peer app can tear down the Zscaler tunnel, force user logout, and toggle packet capture.
Client Connector
CVE-2026-59569 Sep 14, 2026
Input Validation Flaw in Zscaler Client Connector (Android/ChromeOS) Enables Control Bypass An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allows an attacker to potentially bypass Zscaler controls.
Client Connector
CVE-2026-25687 Sep 14, 2026
Race Condition in Zscaler Connector Tunnel Enables Heap Corruption & Exec A race condition in the ZPA tunnel handler of affected versions of Zscaler Client Connector (ZCC) allows a heap corruption, resulting in a denial of service (client crash) and potentially arbitrary code execution in the context of the ZCC process.
Client Connector
CVE-2026-59568 Aug 24, 2026
Zscaler Client Connector RCE via unauthenticated exec Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context.
Client Connector
CVE-2026-59567 Aug 24, 2026
Zscaler Client Connector LPE via Multiple Vulnerabilities Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving an unprivileged user the ability to execute arbitrary code in a privileged context.
Client Connector
CVE-2026-59566 Aug 24, 2026
Local Bof in Zscaler Client Connector Android App DoS A locally exploitable buffer overflow bug can cause a local denial-of-service attack on affected versions of Zscaler Client Connector on Android and ChromeOS.
Client Connector
CVE-2026-59565 Aug 24, 2026
Zscaler Client Connector: Remote Buffer Overflow Enables Kernel DoS A remotely exploitable buffer overflow bug can cause a local and kernel denial-of-service attack on affected versions of Zscaler Client Connector on Windows.
Client Connector
CVE-2026-59564 Aug 24, 2026
Zscaler Client Connector Auth Bypass in Portal Comms An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and the Zscaler Client Connector Portal.
Client Connector
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.