Junglewise Threat Intelligence

CVE-2026-25684: Zscaler Internet Access file type control bypass

CVE-2026-25684 · Severity: medium · CVSS 4.4 · Published 2026-09-18

Vendors: Zscaler.

Executive brief

Zscaler Internet Access is a cloud security service that enforces content and file type policies to block malicious or prohibited files from entering an organization's network. A vulnerability in the file type identification logic could cause the system to incorrectly classify files, allowing prohibited content to bypass security controls in rare situations.

Technical details

A file type attribution issue exists in Zscaler Internet Access File Type Control evaluation rules that may allow improper evaluation of File Type Control policies. The vulnerability results from incorrect file type classification in the policy evaluation engine, which could permit restricted file types to bypass controls under specific circumstances. The issue is described as occurring in rare circumstances and affects the enforcement of File Type Control policies. A patch or update is available to remediate this issue.

Affected products

  • Zscaler Internet Access <UNKNOWN>

Timeline

  • 2026-09-18: disclosed

References