Junglewise Threat Intelligence

CVE-2026-25687: Zscaler Client Connector race condition in ZPA tunnel handler

CVE-2026-25687 · Severity: high · CVSS 8.1 · Published 2026-09-14

Technologies: Zscaler Client Connector. Vendors: Zscaler.

Executive brief

Zscaler Client Connector (ZCC) is a security agent installed on endpoints to route traffic through Zscaler's cloud security platform. A race condition flaw in its ZPA tunnel handler can corrupt memory, causing the client to crash (denial of service) or potentially allowing attackers to execute arbitrary code with the privileges of the ZCC process.

Technical details

A race condition exists in the ZPA tunnel handler component of affected Zscaler Client Connector versions, leading to heap corruption. The vulnerability can be triggered by an attacker with network access to the ZPA tunnel protocol; no authentication is required. Successful exploitation results in client-side denial of service (application crash) and may enable arbitrary code execution in the context of the ZCC process, potentially compromising the endpoint's security posture.

Affected products

  • Zscaler Client Connector <UNKNOWN>

Timeline

  • 2026-09-14: disclosed

References

Related threats