Zscaler
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Zscaler product.
RSS Feeds for Zscaler security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Zscaler products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Zscaler Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 6 vulnerabilities in Zscaler with an average score of 8.3 out of ten. Last year, in 2025 Zscaler had 2 security vulnerabilities published. That is, 4 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 3.07.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 6 | 8.27 |
| 2025 | 2 | 5.20 |
| 2024 | 11 | 7.43 |
| 2023 | 18 | 6.93 |
| 2022 | 0 | 0.00 |
| 2021 | 3 | 0.00 |
It may take a day or so for new Zscaler vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Zscaler Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-59568 | Aug 24, 2026 |
Zscaler Client Connector RCE via unauthenticated execMultiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context. |
|
| CVE-2026-59567 | Aug 24, 2026 |
Zscaler Client Connector LPE via Multiple VulnerabilitiesMultiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving an unprivileged user the ability to execute arbitrary code in a privileged context. |
|
| CVE-2026-59566 | Aug 24, 2026 |
Local Bof in Zscaler Client Connector Android App DoSA locally exploitable buffer overflow bug can cause a local denial-of-service attack on affected versions of Zscaler Client Connector on Android and ChromeOS. |
|
| CVE-2026-59565 | Aug 24, 2026 |
Zscaler Client Connector: Remote Buffer Overflow Enables Kernel DoSA remotely exploitable buffer overflow bug can cause a local and kernel denial-of-service attack on affected versions of Zscaler Client Connector on Windows. |
|
| CVE-2026-59564 | Aug 24, 2026 |
Zscaler Client Connector Auth Bypass in Portal CommsAn authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and the Zscaler Client Connector Portal. |
|
| CVE-2026-22569 | Mar 31, 2026 |
Zscaler Client Connector Windows: Startup Config Skips Traffic InspectionAn incorrect startup configuration of affected versions of Zscaler Client Connector on Windows may cause a limited amount of traffic from being inspected under rare circumstances. |
|
| CVE-2025-54983 | Nov 12, 2025 |
Zscaler Client Connector 4.6/4.7 HC Port BypassA health check port on Zscaler Client Connector on Windows, versions 4.6 < 4.6.0.216 and 4.7 < 4.7.0.47, which under specific circumstances was not released after use, allowed traffic to potentially bypass ZCC forwarding controls. |
|
| CVE-2024-31127 | Jun 04, 2025 |
Privilege Escalation in Zscaler Client Connector <4.2 via Improper Library VerificationAn improper verification of a loaded library in Zscaler Client Connector on Mac < 4.2.0.241 may allow a local attacker to elevate their privileges. |
|
| CVE-2023-28806 | Aug 06, 2024 |
I.S.V in Zscaler Client Connector (Win <4.2.0.190) Enables TamperingAn Improper Validation of signature in Zscaler Client Connector on Windows allows an authenticated user to disable anti-tampering. This issue affects Client Connector on Windows <4.2.0.190. |
|
| CVE-2024-23464 | Aug 06, 2024 |
Zscaler Client Connector Win <4.2.1: Admin PowerShell can disable ZIAIn certain cases, Zscaler Internet Access (ZIA) can be disabled by PowerShell commands with admin rights. This affects Zscaler Client Connector on Windows <4.2.1 |
|