CVE-2026-59568

Summary

Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context.

Affected Software

VendorProductVersion RangeStatus
ZscalerClient Connector0 < Windows: 4.6.0.457, 4.7.0.317, 4.8.0.232, 4.9.0.372affected
ZscalerClient Connector0 < MacOS: 4.5.2.312, 4.7.0.292, 4.8.0.191affected
ZscalerClient Connector0 < Linux: 3.7.2.64, 4.2.1.64affected
ZscalerClient Connector0 < Android: 4.2affected
ZscalerClient Connector0 < ChromeOS: 4.2affected
ZscalerClient Connector0 < iOS: 4.5.1affected

Weaknesses

  • CWE-20: CWE-20 Improper input validation

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: total

References