CVE-2026-25687 PUBLISHED

ZCC race condition in ZPA tunnel handler

Assigner: Zscaler
Reserved: 05.02.2026 Published: 14.09.2026 Updated: 14.09.2026

A race condition in the ZPA tunnel handler of affected versions of Zscaler Client Connector (ZCC) allows a heap corruption, resulting in a denial of service (client crash) and potentially arbitrary code execution in the context of the ZCC process.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 8.1

Product Status

Vendor Zscaler
Product Client Connector
Versions Default: unaffected
  • affected from 4.6 to 4.6.0.486 (excl.)
  • affected from 4.7 to 4.7.0.350 (excl.)
  • affected from 4.8 to 4.8.0.267 (excl.)
  • affected from 4.9 to 4.9.0.412 (excl.)

Credits

  • GovTech Singapore Red Team finder

References

Problem Types

  • CWE-366 Race condition within a thread CWE

Impacts

  • CAPEC-549 Local Execution of Code