Zscaler Client Connector unauthenticated RCE (CVE-2026-59568)
Zscaler's 24 August 2026 CVE record describes multiple Client Connector flaws that allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context. Zscaler scored it 9.1 (CVSS 3.1). The CNA points administrators to the 2026 Client Connector app release summary for fixed builds. Affected version strings in that record include Windows before 4.6.0.457 / 4.7.0.317 / 4.8.0.232 / 4.9.0.372, macOS before 4.5.2.312 / 4.7.0.292 / 4.8.0.191, Linux before 3.7.2.64 / 4.2.1.64, Android and ChromeOS before 4.2, and iOS before 4.5.1. Confirm the exact build from the vendor release summary before declaring a fleet patched. Zscaler's release summary also lists CVE-2026-59564 (auth bypass to the portal), CVE-2026-59567 (local privilege escalation) and CVE-2026-59565 (local/kernel denial of service). Not in CISA KEV at last check.
- Product
- Zscaler Client Connector
- Versions
- Builds before the fixed versions in the 2026 release summary (see CNA version list)
- CVSS
- (CVSS 3.1, Zscaler CNA)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N - Exploited in Australia?
- unknown
- Patch to
- Latest Client Connector build listed in the 2026 release summary for each OS
Primary: CVE-2026-59568 (Zscaler CNA) · Vendor: Zscaler Client Connector 2026 release summary · CVE: CVE-2026-59568, CVE-2026-59564, CVE-2026-59567, CVE-2026-59565
