Description
A remotely exploitable buffer overflow bug can cause a local and kernel denial-of-service attack on affected versions of Zscaler Client Connector on Windows.
Published: 2026-08-24
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (local and kernel)
Action: Patch Immediately
AI Analysis

Impact

A buffer overflow flaw in the Zscaler Client Connector application on Windows can be triggered remotely, leading to application termination and potentially a kernel‑level crash. The vulnerability arose from an unchecked write beyond the bounds of a buffer, which is consistent with CWE‑229 and can disrupt both local and system processes.

Affected Systems

All Windows installations of the Zscaler Client Connector appear to be vulnerable, as the vendor has not specified affected version ranges in the advisory. Until a patch is applied, any currently deployed instance on a Windows host should be considered at risk.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity. EPSS is not available and the vulnerability is not listed in CISA KEV, but the lack of a publicly known exploit does not diminish the need for remediation. Based on the description, it is inferred that attackers can deliver malicious data to the client service over the network, potentially exploiting the overflow to crash the local application or, due to the client’s elevated privileges, to cause a kernel‑level denial of service.

Generated by OpenCVE AI on August 24, 2026 at 20:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Zscaler Client Connector to the latest version available on the vendor’s release summary page.
  • If an update is not yet released, uninstall or disable the Client Connector until a fix is available.
  • Restrict the process privileges of the Client Connector to the minimum set required for its intended operations.

Generated by OpenCVE AI on August 24, 2026 at 20:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Zscaler
Zscaler client Connector
Vendors & Products Zscaler
Zscaler client Connector

Mon, 24 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description A remotely exploitable buffer overflow bug can cause a local and kernel denial-of-service attack on affected versions of Zscaler Client Connector on Windows.
Title Local and kernel denial-of-service
Weaknesses CWE-229
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Zscaler Client Connector
cve-icon MITRE

Status: PUBLISHED

Assigner: Zscaler

Published:

Updated: 2026-08-24T15:18:31.082Z

Reserved: 2026-07-06T06:18:59.633Z

Link: CVE-2026-59565

cve-icon Vulnrichment

Updated: 2026-08-24T15:18:13.699Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-24T14:16:55.830

Modified: 2026-08-28T18:39:48.167

Link: CVE-2026-59565

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T20:45:04Z

Weaknesses
  • CWE-229

    Improper Handling of Values