Junglewise Threat Intelligence

CVE-2026-59565: Zscaler Client Connector buffer overflow denial-of-service

CVE-2026-59565 · Severity: high · CVSS 8.8 · Published 2026-08-24

Technologies: Zscaler Client Connector. Vendors: Zscaler.

Executive brief

Zscaler Client Connector is a network security client deployed on Windows endpoints to enforce security policies. A remotely exploitable buffer overflow in this client can be leveraged to crash the application and the Windows kernel, disrupting endpoint security protections and potentially requiring manual intervention to restore service.

Technical details

The vulnerability is a buffer overflow flaw in Zscaler Client Connector for Windows that can be exploited remotely to trigger both local and kernel denial-of-service conditions. The exact vulnerable component and attack vector are not detailed in the available references, but the remotely exploitable nature suggests the flaw may be reachable via network traffic processed by the client. Successful exploitation results in application crash or kernel-level DoS, disabling the client's security enforcement. Patches are available from Zscaler; affected users should upgrade to patched versions.

Affected products

  • Zscaler Client Connector <UNKNOWN>

Timeline

  • 2026-08-24: disclosed

References

Related threats