Zscaler
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Zscaler product.
RSS Feeds for Zscaler security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Zscaler products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Zscaler Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 11 vulnerabilities in Zscaler with an average score of 7.5 out of ten. Last year, in 2025 Zscaler had 2 security vulnerabilities published. That is, 9 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 2.28.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 11 | 7.48 |
| 2025 | 2 | 5.20 |
| 2024 | 11 | 7.43 |
| 2023 | 18 | 6.93 |
| 2022 | 0 | 0.00 |
| 2021 | 3 | 0.00 |
It may take a day or so for new Zscaler vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Zscaler Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-59563 | Sep 28, 2026 |
Replay Attack on Zscaler MCP Server before v0.7.2 via Unbound HMAC TokensZscaler MCP Server versions 0.7.0 and 0.7.1 has an issue where HMAC confirmation tokens were not bound to the target resource identifier, allowing an MCP client or agent to replay a token generated for one resource to affect another resource of the same type. This issue is fixed in version 0.7.2. |
|
| CVE-2026-25684 | Sep 18, 2026 |
Zscaler Internet Access File Type Control Policy BypassA file type attribution issue in Zscaler Internet Access File Type Control evaluation rules may allow improper evaluation of File Type Control policies in rare circumstances. |
|
| CVE-2026-59570 | Sep 14, 2026 |
Zscaler Client Connector: Peer App can tear down tunnel & force logoutOn affected versions of Zscaler client connector, a pre-installed peer app can tear down the Zscaler tunnel, force user logout, and toggle packet capture. |
|
| CVE-2026-59569 | Sep 14, 2026 |
Input Validation Flaw in Zscaler Client Connector (Android/ChromeOS) Enables Control BypassAn improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allows an attacker to potentially bypass Zscaler controls. |
|
| CVE-2026-25687 | Sep 14, 2026 |
Race Condition in Zscaler Connector Tunnel Enables Heap Corruption & ExecA race condition in the ZPA tunnel handler of affected versions of Zscaler Client Connector (ZCC) allows a heap corruption, resulting in a denial of service (client crash) and potentially arbitrary code execution in the context of the ZCC process. |
|
| CVE-2026-59568 | Aug 24, 2026 |
Zscaler Client Connector RCE via unauthenticated execMultiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context. |
|
| CVE-2026-59567 | Aug 24, 2026 |
Zscaler Client Connector LPE via Multiple VulnerabilitiesMultiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving an unprivileged user the ability to execute arbitrary code in a privileged context. |
|
| CVE-2026-59566 | Aug 24, 2026 |
Local Bof in Zscaler Client Connector Android App DoSA locally exploitable buffer overflow bug can cause a local denial-of-service attack on affected versions of Zscaler Client Connector on Android and ChromeOS. |
|
| CVE-2026-59565 | Aug 24, 2026 |
Zscaler Client Connector: Remote Buffer Overflow Enables Kernel DoSA remotely exploitable buffer overflow bug can cause a local and kernel denial-of-service attack on affected versions of Zscaler Client Connector on Windows. |
|
| CVE-2026-59564 | Aug 24, 2026 |
Zscaler Client Connector Auth Bypass in Portal CommsAn authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and the Zscaler Client Connector Portal. |
|