Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Zscaler — Vulnerabilities & Security Advisories 53

Browse all 53 CVE security advisories affecting Zscaler. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Zscaler operates as a cloud-native security provider, primarily delivering Zero Trust Network Access (ZTNA) and cloud firewall services to secure enterprise traffic. Despite its focus on protecting external threats, the platform has recorded 43 Common Vulnerabilities and Exposures (CVEs), revealing internal security gaps. Historically, these flaws predominantly involve remote code execution and cross-site scripting, with several instances allowing privilege escalation within administrative interfaces. These vulnerabilities suggest that while the external-facing architecture is robust, internal application logic has occasionally failed to enforce strict input validation or access controls. Notable incidents include unauthorized access attempts exploiting these weaknesses, highlighting the risks associated with complex cloud management consoles. The presence of such defects underscores the necessity for rigorous internal code auditing and continuous monitoring, even for vendors specializing in external threat mitigation and secure access solutions.

CVE ID Title CVSS Severity Published
CVE-2024-23463 Anti-Tampering bypass via Repair App functionality — Client Connector CWE-367 8.8 High 2024-04-30
CVE-2024-23482 ZScalerService Local Privilege Escalation — Client Connector CWE-20 7.0 High 2024-03-26
CVE-2023-41973 Lack of input santization on Zscaler Client Connector enables arbitrary code execution — Client Connector CWE-22 7.3 High 2024-03-26
CVE-2023-41972 Revert password check incorrect type validation — Client Connector CWE-280 7.3 High 2024-03-26
CVE-2023-41969 ZSATrayManager Arbitrary File Deletion — Client Connector CWE-61 7.3 High 2024-03-26
CVE-2023-28807 Bypass of ZIA domain fronting detection module through evasion technique — ZIA CWE-295 5.1 Medium 2024-01-31
CVE-2023-28802 Disable Zscaler using machine tunnel restart — Client Connector CWE-354 4.9 Medium 2023-11-21
CVE-2023-28794 PAC Files Exposed to Internet Websites — Client Connector CWE-346 4.3 Medium 2023-11-06
CVE-2023-28805 ZCC on Linux privilege escalation — Client Connector CWE-78 6.7 Medium 2023-10-23
CVE-2023-28804 Linux ZCC allows unsigned updates, allowing elevated Code Execution — Client Connector CWE-347 8.2 High 2023-10-23
CVE-2023-28803 Traffic being bypassed by ZCC by configuring synthetic IP range as local network — Client Connector CWE-290 5.9 Medium 2023-10-23
CVE-2023-28797 LPE using arbitrary file delete with Symlinks — Client Connector CWE-59 6.3 Medium 2023-10-23
CVE-2023-28796 IPC Bypass Through PLT Section in ELF — Client Connector CWE-94 7.1 High 2023-10-23
CVE-2023-28795 Client IPC validation bypass — Client Connector CWE-346 7.8 High 2023-10-23
CVE-2023-28793 Heap Based Buffer Overflow in Library — Client Connector CWE-94 7.8 High 2023-10-23
CVE-2021-26738 Privilege Escalation for ZCC macOS via PATH Variable — Client Connector CWE-426 7.8 High 2023-10-23
CVE-2021-26737 Privilege Escalation Using PID Reuse in ZCC macOS — Client Connector CWE-346 5.5 Medium 2023-10-23
CVE-2021-26736 ZApp Installer Privilege Escalation Vulnerabilities — Client Connector CWE-20 6.7 Medium 2023-10-23
CVE-2021-26735 Untrusted Search Path While Executing REG DELETE by Uninstaller — Client Connector CWE-346 6.7 Medium 2023-10-23
CVE-2021-26734 Junction Delete leading to elevation of privilege — Client Connector CWE-269 4.4 Medium 2023-10-23
CVE-2023-28801 Improper SAML signature verification — ZIA Admin Portal CWE-347 9.6 Critical 2023-08-31
CVE-2023-28800 Output encoding missing in redrurl parameter — Client Connector CWE-79 8.1 High 2023-06-22
CVE-2023-28799 Zscaler Client Connector 输入验证错误漏洞 — Client Connector CWE-1287 8.2 High 2023-06-22

This page lists every published CVE security advisory associated with Zscaler. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.