CVE-2026-59568 PUBLISHED

Remote Code Execution

Assigner: Zscaler
Reserved: 06.07.2026 Published: 24.08.2026 Updated: 24.08.2026

Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS Score: 9.1

Product Status

Vendor Zscaler
Product Client Connector
Versions Default: unaffected
  • affected from 0 to Windows: 4.6.0.457, 4.7.0.317, 4.8.0.232, 4.9.0.372 (excl.)
  • affected from 0 to MacOS: 4.5.2.312, 4.7.0.292, 4.8.0.191 (excl.)
  • affected from 0 to Linux: 3.7.2.64, 4.2.1.64 (excl.)
  • affected from 0 to Android: 4.2 (excl.)
  • affected from 0 to ChromeOS: 4.2 (excl.)
  • affected from 0 to iOS: 4.5.1 (excl.)

References

Problem Types

  • CWE-20 Improper input validation CWE

Impacts

  • CAPEC-253 Remote Code Inclusion