CVE-2026-59566 PUBLISHED

Local denial-of-service

Assigner: Zscaler
Reserved: 06.07.2026 Published: 24.08.2026 Updated: 24.08.2026

A locally exploitable buffer overflow bug can cause a local denial-of-service attack on affected versions of Zscaler Client Connector on Android and ChromeOS.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 8.4

Product Status

Vendor Zscaler
Product Client Connector
Versions Default: affected
  • affected from 0 to Android: 4.2 (excl.)
  • affected from 0 to ChromeOS: 4.2 (excl.)

References

Problem Types

  • CWE-229 Improper handling of values CWE

Impacts

  • CAPEC-100 Overflow Buffers