{"id":"CVE-2026-25687","title":"A race condition in the ZPA tunnel handler of affected versions of Zscaler Client Connector (ZCC) allows a heap corruption, resulting in a denial of service (client crash) and potentially arbitrary code execution in the context of the ZC…","summary":"A race condition in the ZPA tunnel handler of affected versions of Zscaler Client Connector (ZCC) allows a heap corruption, resulting in a denial of service (client crash) and potentially arbitrary code execution in the context of the ZC…","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-366"],"vendor":"Zscaler","product":"Client Connector","affected":["client_connector >= 4.6 < 4.6.0.486","client_connector >= 4.7 < 4.7.0.350","client_connector >= 4.8 < 4.8.0.267","client_connector >= 4.9 < 4.9.0.412"],"published":"2026-09-14","updated":"2026-09-18","sourceUpdated":"2026-09-18T19:08:02.707","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-25687","references":[{"url":"https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026","label":"cve@zscaler.com"}],"tags":["nvd","cve.org"],"epss":0.0038,"epssPercentile":0.29143,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-14T15:33:09.117567Z"},"ingestedAt":"2026-09-14T15:23:07.423Z","slug":"CVE-2026-25687","body":"## Overview\n\nA race condition in the ZPA tunnel handler of affected versions of Zscaler Client Connector (ZCC) allows a heap corruption, resulting in a denial of service (client crash) and potentially arbitrary code execution in the context of the ZCC process.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":44.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}