Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Zscaler — Vulnerabilities & Security Advisories 53

Browse all 53 CVE security advisories affecting Zscaler. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Zscaler operates as a cloud-native security provider, primarily delivering Zero Trust Network Access (ZTNA) and cloud firewall services to secure enterprise traffic. Despite its focus on protecting external threats, the platform has recorded 43 Common Vulnerabilities and Exposures (CVEs), revealing internal security gaps. Historically, these flaws predominantly involve remote code execution and cross-site scripting, with several instances allowing privilege escalation within administrative interfaces. These vulnerabilities suggest that while the external-facing architecture is robust, internal application logic has occasionally failed to enforce strict input validation or access controls. Notable incidents include unauthorized access attempts exploiting these weaknesses, highlighting the risks associated with complex cloud management consoles. The presence of such defects underscores the necessity for rigorous internal code auditing and continuous monitoring, even for vendors specializing in external threat mitigation and secure access solutions.

CVE ID Title CVSS Severity Published
CVE-2026-59563 HMAC Confirmation Token Unbinding in zscaler-mcp-server — zscaler-mcp-server CWE-305 4.6 Medium 2026-09-28
CVE-2026-25684 File Type Control rule bypass — ZIA File Type Control CWE-20 4.4 Medium 2026-09-18
CVE-2026-59570 Android ZCC denial of service — Client Connector CWE-20 7.5 High 2026-09-14
CVE-2026-59569 Android ZCC VPN API method privilege escalation — Client Connector CWE-20 8.1 High 2026-09-14
CVE-2026-25687 ZCC race condition in ZPA tunnel handler — Client Connector CWE-366 8.1 High 2026-09-14
CVE-2026-59568 Remote Code Execution — Client Connector CWE-20 9.1 Critical 2026-08-24
CVE-2026-59567 Local privilege escalation — Client Connector CWE-280 8.8 High 2026-08-24
CVE-2026-59566 Local denial-of-service — Client Connector CWE-229 8.4 High 2026-08-24
CVE-2026-59565 Local and kernel denial-of-service — Client Connector CWE-229 8.8 High 2026-08-24
CVE-2026-59564 Authentication bypass between ZCC and client connector portal — Client Connector CWE-304 9.1 Critical 2026-08-24
CVE-2026-22569 Incorrect startup configuration in ZCC — Zscaler Client Connector CWE-1289 5.4 Medium 2026-03-31
CVE-2026-22567 ZIA Admin UI Input Validation Bug — ZIA Admin UI CWE-20 7.6 High 2026-02-23
CVE-2026-22568 Unauthorized information retrieval in ZIA Admin UI — ZIA Admin UI CWE-20 5.5 Medium 2026-02-23
CVE-2025-54983 Health check port on ZCC allows tunnel bypass — Zscaler Client Connector CWE-772 5.2 Medium 2025-11-12
CVE-2025-54982 SAML 2.0 Public Key Validation Issue — Authentication Server CWE-347 9.6 Critical 2025-08-05
CVE-2024-31127 MacOS Zscaler Client Connector Local Privilege Escalation — Client Connector CWE-346 7.3 High 2025-06-04
CVE-2023-28806 Signature validation error in DLL allows disabling anti-tampering protection — Client Connector CWE-347 5.7 Medium 2024-08-06
CVE-2024-23483 Local Privilege Escalation via lack of input validation — Client Connector CWE-20 7.0 High 2024-08-06
CVE-2024-23460 Incorrect signature validation of package — Client Connector CWE-347 6.4 Medium 2024-08-06
CVE-2024-23464 Zscaler bypass with administrative privileges on Windows — Client Connector CWE-281 7.2 High 2024-08-06
CVE-2024-23458 Local Privilege Escalation on Zscaler Client Connector on Windows — Client Connector CWE-346 7.3 High 2024-08-06
CVE-2024-23456 Signature validation issue leads to Anti-Tampering bypass — Client Connector CWE-347 7.8 High 2024-08-06
CVE-2024-23462 ZCC Mac validinstaller file integrity check missing — Client Connector CWE-354 3.3 Low 2024-05-02
CVE-2024-23461 ZCC macOS Upgrade ZIP Bomb DoS — Client Connector CWE-354 4.2 Medium 2024-05-02
CVE-2024-23459 Multiple Arbitrary Creates/Overwrites by link following — Client Connector CWE-59 7.1 High 2024-05-02
CVE-2023-41971 Windows ZCC Upgrade DoS And Privilege Escalation Through RPC Control — Client Connector CWE-59 5.3 Medium 2024-05-02
CVE-2023-41970 Repair App local code execution with arbitrary privileges — Client Connector CWE-354 6.0 Medium 2024-05-02
CVE-2023-28798 Out-of-bounds write to heap in pacparser — Client Connector CWE-122 6.5 Medium 2024-05-02
CVE-2024-23480 Insecure MacOS code sign check fallback — Client Connector CWE-347 7.5 High 2024-05-01
CVE-2024-23457 Anti-tampering can be disabled with uninstall password enforced — Client Connector CWE-269 7.8 High 2024-05-01

This page lists every published CVE security advisory associated with Zscaler. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.