在受影响的 Android 和 ChromeOS 版本的 Zscaler 客户端连接器中,存在一个本地可利用的缓冲区溢出漏洞,可能导致本地拒绝服务攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Zscaler | Client Connector | < Android: 4.2 |
affected |
< ChromeOS: 4.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Zscaler | Client Connector | 0 ~ Android: 4.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-59564 | 9.1 CRITICAL | Authentication bypass between ZCC and client connector portal |
| CVE-2026-59568 | 9.1 CRITICAL | Remote Code Execution |
| CVE-2026-59565 | 8.8 HIGH | Local and kernel denial-of-service |
| CVE-2026-59567 | 8.8 HIGH | Local privilege escalation |
No comments yet