Junglewise Threat Intelligence

CVE-2026-59564: Zscaler Client Connector authentication bypass

CVE-2026-59564 · Severity: critical · CVSS 9.1 · Published 2026-08-24

Technologies: Zscaler Client Connector. Vendors: Zscaler.

Executive brief

Zscaler Client Connector is a software agent that manages secure network access for remote employees. An authentication bypass vulnerability in communications between the client and its portal could allow an attacker to impersonate legitimate users or gain unauthorized access to protected resources, potentially compromising employee data and network security.

Technical details

An authentication bypass vulnerability exists in the communications protocol between affected versions of Zscaler Client Connector and the Zscaler Client Connector Portal. The vulnerability allows attackers to circumvent authentication mechanisms without valid credentials. The exact attack vector and preconditions are not detailed in the available advisory text, but the critical severity rating suggests an easily exploitable flaw with significant impact. Patches are available through Zscaler client connector releases.

Affected products

  • Zscaler Client Connector <UNKNOWN>

Timeline

  • 2026-08-24: disclosed

References

Related threats