VulnSea

Zscaler has 5 CVEs on record. 4 were published in the last 90 days. The busiest recent month was September 2026 with 4. The median CVSS is 7.5 (high). None have a confirmed exploitation report. The most common weakness class is CWE-20 (3). Most affected products: Client Connector (3), ZIA File Type Control (1), client_connector (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
Last 90 days
4 prev 1

Products

  • Client Connector 3
  • ZIA File Type Control 1
  • client_connector 1
5
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

Zscaler vulnerabilities

CVEs affecting Zscaler, newest first. Open any entry for full detail, references, and exploit status.

5 CVEsRSS

CVE-2026-25684Medium· 4.4
4d ago

A file type attribution issue in Zscaler Internet Access File Type Control evaluation rules may allow improper evaluation of File Type Control policies in rare circumstances.

A file type attribution issue in Zscaler Internet Access File Type Control evaluation rules may allow improper evaluation of File Type Control policies in rare circumstances.

SunlitZscaler · ZIA File Type ControlEPSS 0.18%via NVD
CVE-2026-59570High· 7.5
1w ago

On affected versions of Zscaler client connector, a pre-installed peer app can tear down the Zscaler tunnel, force user logout, and toggle packet capture.

On affected versions of Zscaler client connector, a pre-installed peer app can tear down the Zscaler tunnel, force user logout, and toggle packet capture.

TwilightZscaler · Client ConnectorEPSS 0.09%via NVD
CVE-2026-59569High· 8.1
1w ago

An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allows an attacker to potentially bypass Zscaler controls.

An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allows an attacker to potentially bypass Zscaler controls.

TwilightZscaler · Client ConnectorEPSS 0.12%via NVD
CVE-2026-25687High· 8.1
1w ago

A race condition in the ZPA tunnel handler of affected versions of Zscaler Client Connector (ZCC) allows a heap corruption, resulting in a denial of service (client crash) and potentially arbitrary code execution in the context of the ZC…

A race condition in the ZPA tunnel handler of affected versions of Zscaler Client Connector (ZCC) allows a heap corruption, resulting in a denial of service (client crash) and potentially arbitrary code execution in the context of the ZC…

TwilightZscaler · Client ConnectorEPSS 0.23%via NVD
CVE-2026-22569Medium· 5.4
5mo ago

An incorrect startup configuration of affected versions of Zscaler Client Connector on Windows may cause a limited amount of traffic from being inspected under rare circumstances.

An incorrect startup configuration of affected versions of Zscaler Client Connector on Windows may cause a limited amount of traffic from being inspected under rare circumstances.

Sunlitzscaler · client_connectorEPSS 0.18%via NVD
Zscaler vulnerabilities (CVEs) · VulnSea