logo

Critical Zscaler Client Connector Vulnerability Allows Remote Code Execution Without Login

ID: c16343df-63a5-5eac-9af5-a29fc755d885

STIX ID: report--c16343df-63a5-5eac-9af5-a29fc755d885

Feed Name: Cyber Press

Threat Score
80/100

Date Published: 2026-08-25

Date Updated: 2026-08-25

Author: Tamilselvan

...
...

A critical remote code execution vulnerability (CVE-2026-59568, CVSS 9.1) affecting Zscaler Client Connector on managed Windows endpoints can be exploited remotely without authentication or user interaction. Zscaler's June 1, 2026 releases (including Windows version 4.8.0.232 and later builds listed) include fixes; administrators are advised to inventory endpoints, verify versions, and review endpoint telemetry for anomalous activity because successful exploitation could allow attackers to gain an initial foothold and compromise confidentiality and integrity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.