Description
Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context.
Published: 2026-08-24
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Immediately
AI Analysis

Impact

This vulnerability involves multiple flaws in Zscaler Client Connector that allow a remote, unauthenticated, unprivileged user to execute arbitrary code within the ZCC process. The weakness is an instance of improper input validation (CWE‑20). Successful exploitation could compromise the confidentiality, integrity, and availability of the host running the client, potentially granting full control of the operating system.

Affected Systems

The affected product is Zscaler Client Connector. Specific affected versions are not disclosed in the CVE data; it applies to all pre‑release‑summary‑2026 releases that have not yet been updated by the vendor.

Risk and Exploitability

The high CVSS score of 9.1 indicates a severe risk. EPSS information is not available, and the vulnerability is not currently listed in CISA KEV. Based on the description, the likely attack vector is remote network access to the Client Connector service, and no authentication or privilege escalation is required. An attacker can reach the vulnerable component from any system that can communicate with the client, triggering code execution with the privileges of the ZCC process.

Generated by OpenCVE AI on August 24, 2026 at 20:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Zscaler Client Connector update per the vendor release summary.
  • If an update cannot be applied immediately, block inbound traffic to the Client Connector management port or disable the remote management feature to prevent external exploitation.
  • Limit the execution of the client to trusted users only, ensuring that only local, authenticated users have permission to run the application.

Generated by OpenCVE AI on August 24, 2026 at 20:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Zscaler
Zscaler client Connector
Vendors & Products Zscaler
Zscaler client Connector

Mon, 24 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context.
Title Remote Code Execution
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Zscaler Client Connector
cve-icon MITRE

Status: PUBLISHED

Assigner: Zscaler

Published:

Updated: 2026-08-25T03:56:59.614Z

Reserved: 2026-07-06T06:18:59.633Z

Link: CVE-2026-59568

cve-icon Vulnrichment

Updated: 2026-08-24T15:15:26.148Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-24T14:16:56.210

Modified: 2026-08-28T18:39:48.167

Link: CVE-2026-59568

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T20:15:04Z

Weaknesses
  • CWE-20

    Improper Input Validation