Skip to content
Security Alerts

CVE-2026-59568 and CVE-2026-59564: remote code execution and authentication bypass in Zscaler Client Connector

The Zscaler Client Connector agent contains flaws letting an unauthenticated, unprivileged user execute arbitrary code in the ZCC context and bypass authentication against the ZCC Portal...

Summary

ParameterValue
CVE IDCVE-2026-59568, CVE-2026-59564
Alert SourceGitHub Advisory - critical vulnerability (CNA: Zscaler)
CVE Publication Year2026
Date Published2026-08-24
VendorZscaler
ProductZscaler Client Connector (ZCC)
Affected versionsas listed by the vendor in Client Connector App Release Summary 2026
CVSS Score9.1 (Critical)
EPSS ScoreNo data (CVEs published 2026-08-24)
CISA KEVNo
RansomwareNot confirmed

Vulnerability Description

Zscaler Client Connector (ZCC) is the agent installed on workstations and mobile devices that steers user traffic into the Zscaler cloud (ZIA / ZPA). In a Zero Trust architecture it is the policy enforcement point — it runs on every corporate laptop and holds the privileges needed to intercept and redirect network traffic.

Zscaler disclosed two vulnerabilities:

CVE-2026-59568 — remote code execution (CVSS 9.1). Multiple flaws in affected ZCC versions let an unauthenticated, unprivileged user execute arbitrary code in the Client Connector context. Because the agent runs with high privileges on the workstation, this is a path to endpoint takeover and privilege escalation.

CVE-2026-59564 — authentication bypass (CVSS 9.1). A flaw in communication between the Client Connector and the ZCC Portal allows authentication to be bypassed. This targets the agent’s management plane — the mechanism that decides which policy is enforced on a device.

Both were published by Zscaler itself (as CNA) in the 2026 ZCC application release summary. Technical detail and affected build numbers are kept in customer-facing documentation.

Operational note: Zscaler does not publish a complete list of affected versions in NVD. Confirm the scope in the Zscaler customer portal or with your technical account manager — do not assume your installation is safe simply because the agent auto-updates.

Required Actions

  1. Upgrade Zscaler Client Connector to the fixed release named in the Client Connector App Release Summary 2026. Check what is actually deployed across the fleet in the ZCC console (Administration → Client Connector Support → Device Overview).
  2. Review the agent update policy. Many organisations pin ZCC to a specific version to avoid regressions — in that case auto-update will not fire and the fleet stays on a vulnerable build.
  3. Confirm with Zscaler which versions are covered by both CVEs before you close this out.
  4. Check ZCC logs for unusual device enrolments or policy assignment changes — an authentication bypass against the portal (CVE-2026-59564) leaves its trace there.
  5. Treat this as a process test: a vulnerability in an EDR/SASE agent by definition affects every workstation in the company, so time-to-patch is a real measure of endpoint vulnerability management maturity.

Who Is Affected?

Organisations using the Zscaler platform — Zscaler Internet Access or Zscaler Private Access. These are large enterprises that replaced the classic VPN-and-perimeter-firewall model with a SASE / Zero Trust architecture: banking, telecommunications, energy, logistics operators, and local subsidiaries of multinationals where the standard was set by headquarters.

What makes this alert distinctive is that the number of vulnerable devices equals the number of corporate workstations — a security agent is wherever the user is. A vulnerability in a protective tool carries extra weight, because it runs with high privileges and is trusted by default both by the operating system and by the SOC team.

Sources


Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.

Learn More

Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist