---
id: CVE-2026-25684
title: >-
  A file type attribution issue in Zscaler Internet Access File Type Control
  evaluation rules may allow improper evaluation of File Type Control policies
  in rare circumstances.
summary: >-
  A file type attribution issue in Zscaler Internet Access File Type Control
  evaluation rules may allow improper evaluation of File Type Control policies
  in rare circumstances.
severity: medium
cvss: 4.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-20
vendor: Zscaler
product: ZIA File Type Control
affected:
  - zia_file_type_control
published: '2026-09-18'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:08:02.707'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-25684'
references:
  - url: 'https://help.zscaler.com/zia/release-upgrade-summary-2026'
    label: cve@zscaler.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-18T17:46:54.756551Z'
ingestedAt: '2026-09-18T14:43:13.072Z'
epss: 0.00197
epssPercentile: 0.08325
---

## Overview

A file type attribution issue in Zscaler Internet Access File Type Control evaluation rules may allow improper evaluation of File Type Control policies in rare circumstances.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
