Description
On affected versions of Zscaler client connector, a pre-installed peer app can tear down the Zscaler tunnel, force user logout, and toggle packet capture.
Published: 2026-09-14
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
First Time appeared Zscaler
Zscaler client Connector
Vendors & Products Zscaler
Zscaler client Connector

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description On affected versions of Zscaler client connector, a pre-installed peer app can tear down the Zscaler tunnel, force user logout, and toggle packet capture.
Title Android ZCC denial of service
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Zscaler Client Connector
cve-icon MITRE

Status: PUBLISHED

Assigner: Zscaler

Published:

Updated: 2026-09-14T15:32:24.258Z

Reserved: 2026-07-06T06:18:59.633Z

Link: CVE-2026-59570

cve-icon Vulnrichment

Updated: 2026-09-14T15:32:21.025Z

cve-icon NVD

Status : Received

Published: 2026-09-14T15:17:06.720

Modified: 2026-09-14T16:17:16.343

Link: CVE-2026-59570

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T06:00:21Z

Weaknesses
  • CWE-20

    Improper Input Validation