Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Client Connector — Vulnerabilities & Security Advisories 44

All 44 CVE vulnerabilities found in Client Connector, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities specifically affecting the Client Connector component. It collects data on various weakness types, including remote code execution, information disclosure, and denial of service issues, covering the period from the initial release of the connector to the latest patched version. Readers can use this resource to track vendor security advisories, understand specific weakness classes, and review the complete vulnerability history for this product. The data is organized by CVE identifier and severity, allowing analysts to filter results by date or impact. This compilation serves as a centralized reference for security teams managing the Client Connector, providing a clear view of past security incidents and current exposure. By reviewing these records, organizations can identify recurring failure patterns and assess whether their deployed versions are protected against known exploits. The page focuses exclusively on confirmed vulnerabilities with published advisories, excluding theoretical or unverified reports. Use this aggregation to align your patch management strategy with documented security flaws, ensuring that critical weaknesses are addressed promptly. The collection is maintained to reflect the most recent security updates from the vendor.

Vendor: Zscaler

CVE ID Title CVSS Severity Published
CVE-2026-59570 Android ZCC denial of service CWE-20 7.5 High 2026-09-14
CVE-2026-59569 Android ZCC VPN API method privilege escalation CWE-20 8.1 High 2026-09-14
CVE-2026-25687 ZCC race condition in ZPA tunnel handler CWE-366 8.1 High 2026-09-14
CVE-2026-59568 Remote Code Execution CWE-20 9.1 Critical 2026-08-24
CVE-2026-59567 Local privilege escalation CWE-280 8.8 High 2026-08-24
CVE-2026-59566 Local denial-of-service CWE-229 8.4 High 2026-08-24
CVE-2026-59565 Local and kernel denial-of-service CWE-229 8.8 High 2026-08-24
CVE-2026-59564 Authentication bypass between ZCC and client connector portal CWE-304 9.1 Critical 2026-08-24
CVE-2024-31127 MacOS Zscaler Client Connector Local Privilege Escalation CWE-346 7.3 High 2025-06-04
CVE-2023-28806 Signature validation error in DLL allows disabling anti-tampering protection CWE-347 5.7 Medium 2024-08-06
CVE-2024-23483 Local Privilege Escalation via lack of input validation CWE-20 7.0 High 2024-08-06
CVE-2024-23460 Incorrect signature validation of package CWE-347 6.4 Medium 2024-08-06
CVE-2024-23464 Zscaler bypass with administrative privileges on Windows CWE-281 7.2 High 2024-08-06
CVE-2024-23458 Local Privilege Escalation on Zscaler Client Connector on Windows CWE-346 7.3 High 2024-08-06
CVE-2024-23456 Signature validation issue leads to Anti-Tampering bypass CWE-347 7.8 High 2024-08-06
CVE-2024-23462 ZCC Mac validinstaller file integrity check missing CWE-354 3.3 Low 2024-05-02
CVE-2024-23461 ZCC macOS Upgrade ZIP Bomb DoS CWE-354 4.2 Medium 2024-05-02
CVE-2024-23459 Multiple Arbitrary Creates/Overwrites by link following CWE-59 7.1 High 2024-05-02
CVE-2023-41971 Windows ZCC Upgrade DoS And Privilege Escalation Through RPC Control CWE-59 5.3 Medium 2024-05-02
CVE-2023-41970 Repair App local code execution with arbitrary privileges CWE-354 6.0 Medium 2024-05-02
CVE-2023-28798 Out-of-bounds write to heap in pacparser CWE-122 6.5 Medium 2024-05-02
CVE-2024-23480 Insecure MacOS code sign check fallback CWE-347 7.5 High 2024-05-01
CVE-2024-23457 Anti-tampering can be disabled with uninstall password enforced CWE-269 7.8 High 2024-05-01
CVE-2024-23463 Anti-Tampering bypass via Repair App functionality CWE-367 8.8 High 2024-04-30
CVE-2024-23482 ZScalerService Local Privilege Escalation CWE-20 7.0 High 2024-03-26
CVE-2023-41973 Lack of input santization on Zscaler Client Connector enables arbitrary code execution CWE-22 7.3 High 2024-03-26
CVE-2023-41972 Revert password check incorrect type validation CWE-280 7.3 High 2024-03-26
CVE-2023-41969 ZSATrayManager Arbitrary File Deletion CWE-61 7.3 High 2024-03-26
CVE-2023-28802 Disable Zscaler using machine tunnel restart CWE-354 4.9 Medium 2023-11-21
CVE-2023-28794 PAC Files Exposed to Internet Websites CWE-346 4.3 Medium 2023-11-06

All 44 known CVE vulnerabilities affecting Client Connector with full Chinese analysis, references, and POCs where available.