Executive brief
Zscaler Client Connector is endpoint security software that protects user devices and corporate networks by routing traffic through Zscaler's cloud. Multiple flaws in recent versions allow unauthenticated attackers to execute arbitrary code with the privileges of the Client Connector process, potentially compromising infected systems and corporate network access.
Technical details
Multiple remote code execution vulnerabilities in Zscaler Client Connector allow unauthenticated, unprivileged users to execute arbitrary code in the ZCC context. The vulnerabilities are network-reachable and require no user interaction or prior authentication. Successful exploitation grants an attacker code execution in the security context of the Client Connector application, which runs with elevated system privileges on the endpoint. Zscaler has published patched versions addressing these flaws; affected users should upgrade immediately.
Affected products
- Zscaler Client Connector
Timeline
- 2026-08-24: disclosed