← Terug naar overzicht

CVE-2026-59568 describes multiple vulnerabilities affecting Zscaler Client Connector (ZCC) that enable remote code execution. The flaws allow an unauthenticated, unprivileged remote user to execute arbitrary code within the ZCC context. The vulnerabilities are present in affected versions of the Zscaler Client Connector software. No authentication or special privileges are required to exploit these vulnerabilities, making them particularly severe. The issue is documented on the NVD and Zscaler's own release summary page. Zscaler has published a Client Connector App Release Summary for 2026 that likely contains patched versions. The criticality is rated High due to the unauthenticated RCE nature of the vulnerability. Organizations using affected versions of Zscaler Client Connector should update immediately.

Affected products

  • Zscaler Client Connector

Related CVE's

  • CVE-2026-59568

Categories

  • Network Infrastructure
  • Security Tools
  • Zero-Day Vulnerabilities