Summary
| Parameter | Value |
|---|---|
| CVE ID | CVE-2026-59568, CVE-2026-59564 |
| Alert Source | GitHub Advisory - critical vulnerability (CNA: Zscaler) |
| CVE Publication Year | 2026 |
| Date Published | 2026-08-24 |
| Vendor | Zscaler |
| Product | Zscaler Client Connector (ZCC) |
| Affected versions | as listed by the vendor in Client Connector App Release Summary 2026 |
| CVSS Score | 9.1 (Critical) |
| EPSS Score | No data (CVEs published 2026-08-24) |
| CISA KEV | No |
| Ransomware | Not confirmed |
Vulnerability Description
Zscaler Client Connector (ZCC) is the agent installed on workstations and mobile devices that steers user traffic into the Zscaler cloud (ZIA / ZPA). In a Zero Trust architecture it is the policy enforcement point — it runs on every corporate laptop and holds the privileges needed to intercept and redirect network traffic.
Zscaler disclosed two vulnerabilities:
CVE-2026-59568 — remote code execution (CVSS 9.1). Multiple flaws in affected ZCC versions let an unauthenticated, unprivileged user execute arbitrary code in the Client Connector context. Because the agent runs with high privileges on the workstation, this is a path to endpoint takeover and privilege escalation.
CVE-2026-59564 — authentication bypass (CVSS 9.1). A flaw in communication between the Client Connector and the ZCC Portal allows authentication to be bypassed. This targets the agent’s management plane — the mechanism that decides which policy is enforced on a device.
Both were published by Zscaler itself (as CNA) in the 2026 ZCC application release summary. Technical detail and affected build numbers are kept in customer-facing documentation.
Operational note: Zscaler does not publish a complete list of affected versions in NVD. Confirm the scope in the Zscaler customer portal or with your technical account manager — do not assume your installation is safe simply because the agent auto-updates.
Required Actions
- Upgrade Zscaler Client Connector to the fixed release named in the Client Connector App Release Summary 2026. Check what is actually deployed across the fleet in the ZCC console (Administration → Client Connector Support → Device Overview).
- Review the agent update policy. Many organisations pin ZCC to a specific version to avoid regressions — in that case auto-update will not fire and the fleet stays on a vulnerable build.
- Confirm with Zscaler which versions are covered by both CVEs before you close this out.
- Check ZCC logs for unusual device enrolments or policy assignment changes — an authentication bypass against the portal (CVE-2026-59564) leaves its trace there.
- Treat this as a process test: a vulnerability in an EDR/SASE agent by definition affects every workstation in the company, so time-to-patch is a real measure of endpoint vulnerability management maturity.
Who Is Affected?
Organisations using the Zscaler platform — Zscaler Internet Access or Zscaler Private Access. These are large enterprises that replaced the classic VPN-and-perimeter-firewall model with a SASE / Zero Trust architecture: banking, telecommunications, energy, logistics operators, and local subsidiaries of multinationals where the standard was set by headquarters.
What makes this alert distinctive is that the number of vulnerable devices equals the number of corporate workstations — a security agent is wherever the user is. A vulnerability in a protective tool carries extra weight, because it runs with high privileges and is trusted by default both by the operating system and by the SOC team.
Sources
- NVD - CVE-2026-59568
- NVD - CVE-2026-59564
- Zscaler - Client Connector App Release Summary 2026
- Zscaler Trust - Security Advisories
Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.
