Zscaler
Zscaler Client Connector: vulnerabilidades y CVE
Zscaler Client Connector tiene 51 vulnerabilidades publicadas, 10 de ellas en los últimos 12 meses. 8 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE51
Últimos 12 meses10
Críticas8
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-59570 | Alta (7.5) | 0.13% | — | 14 sept 2026 | On affected versions of Zscaler client connector, a pre-installed peer app can tear down the Zscaler tunnel, force user logout, and toggle packet capture. |
| CVE-2026-59569 | Alta (8.1) | 0.18% | — | 14 sept 2026 | An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allows an attacker to potentially bypass Zscaler controls. |
| CVE-2026-25687 | Alta (8.1) | 0.38% | — | 14 sept 2026 | A race condition in the ZPA tunnel handler of affected versions of Zscaler Client Connector (ZCC) allows a heap corruption, resulting in a denial of service (client crash) and potentially arbitrary code execution in the… |
| CVE-2026-59568 | Crítica (9.1) | 0.66% | — | 24 ago 2026 | Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context. |
| CVE-2026-59567 | Alta (8.8) | 0.15% | — | 24 ago 2026 | Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving an unprivileged user the ability to execute arbitrary code in a privileged context. |
| CVE-2026-59566 | Alta (8.4) | 0.18% | — | 24 ago 2026 | A locally exploitable buffer overflow bug can cause a local denial-of-service attack on affected versions of Zscaler Client Connector on Android and ChromeOS. |
| CVE-2026-59565 | Alta (8.8) | 0.48% | — | 24 ago 2026 | A remotely exploitable buffer overflow bug can cause a local and kernel denial-of-service attack on affected versions of Zscaler Client Connector on Windows. |
| CVE-2026-59564 | Crítica (9.1) | 0.53% | — | 24 ago 2026 | An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and the Zscaler Client Connector Portal. |
| CVE-2026-22569 | Media (5.3) | 0.18% | — | 31 mar 2026 | An incorrect startup configuration of affected versions of Zscaler Client Connector on Windows may cause a limited amount of traffic from being inspected under rare circumstances. |
| CVE-2025-54983 | Media (5.2) | 0.12% | — | 12 nov 2025 | A health check port on Zscaler Client Connector on Windows, versions 4.6 < 4.6.0.216 and 4.7 < 4.7.0.47, which under specific circumstances was not released after use, allowed traffic to potentially bypass ZCC… |
| CVE-2024-31127 | Alta (7.3) | 0.10% | — | 4 jun 2025 | An improper verification of a loaded library in Zscaler Client Connector on Mac < 4.2.0.241 may allow a local attacker to elevate their privileges. |
| CVE-2024-23483 | Crítica (9.8) | 0.75% | — | 6 ago 2024 | An Improper Input Validation vulnerability in Zscaler Client Connector on MacOS allows OS Command Injection. This issue affects Zscaler Client Connector on MacOS <4.2. |
| CVE-2024-23464 | Media (4.9) | 0.43% | — | 6 ago 2024 | In certain cases, Zscaler Internet Access (ZIA) can be disabled by PowerShell commands with admin rights. This affects Zscaler Client Connector on Windows <4.2.1 |
| CVE-2024-23460 | Alta (7.8) | 0.13% | — | 6 ago 2024 | The Zscaler Updater process does not validate the digital signature of the installer before execution, allowing arbitrary code to be locally executed. This affects Zscaler Client Connector on MacOS <4.2. |
| CVE-2024-23458 | Alta (7.8) | 0.11% | — | 6 ago 2024 | While copying individual autoupdater log files, reparse point check was missing which could result into crafted attacks, potentially leading to a local privilege escalation. This issue affects Zscaler Client Connector… |
| CVE-2024-23456 | Alta (7.5) | 0.23% | — | 6 ago 2024 | Anti-tampering can be disabled under certain conditions without signature validation. This affects Zscaler Client Connector <4.2.0.190 with anti-tampering enabled. |
| CVE-2023-28806 | Media (6.5) | 0.19% | — | 6 ago 2024 | An Improper Validation of signature in Zscaler Client Connector on Windows allows an authenticated user to disable anti-tampering. This issue affects Client Connector on Windows <4.2.0.190. |
| CVE-2024-3661 | Alta (7.6) | 4.1% | — | 6 may 2024 | DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical… |
| CVE-2024-23462 | Alta (7.5) | 0.19% | — | 2 may 2024 | An Improper Validation of Integrity Check Value vulnerability in Zscaler Client Connector on MacOS allows a denial of service of the Client Connector binary and thus removing client functionality.This issue affects… |
| CVE-2024-23461 | Media (5.5) | 0.11% | — | 2 may 2024 | An Improper Validation of Integrity Check Value vulnerability in Zscaler Client Connector on MacOS during the upgrade process may allow a Local Execution of Code.This issue affects Client Connector on MacOS: before 3.4. |
| CVE-2024-23459 | Crítica (9.8) | 0.47% | — | 2 may 2024 | An Improper Link Resolution Before File Access ('Link Following') vulnerability in Zscaler Client Connector on Mac allows a system file to be overwritten.This issue affects Zscaler Client Connector on Mac : before 3.7. |
| CVE-2023-41971 | Alta (7.8) | 0.19% | — | 2 may 2024 | An Improper Link Resolution Before File Access ('Link Following') vulnerability in Zscaler Client Connector on Windows allows a system file to be overwritten.This issue affects Client Connector on Windows: before 3.7. |
| CVE-2023-41970 | Alta (7.8) | 0.11% | — | 2 may 2024 | An Improper Validation of Integrity Check Value vulnerability in Zscaler Client Connector on Windows during the Repair App functionality may allow Local Execution of Code.This issue affects Client Connector on Windows:… |
| CVE-2023-28798 | Crítica (9.8) | 0.43% | — | 2 may 2024 | An out-of-bounds write to heap in the pacparser library on Zscaler Client Connector on Mac may lead to arbitrary code execution. |
| CVE-2024-23480 | Crítica (9.8) | 0.30% | — | 1 may 2024 | A fallback mechanism in code sign checking on macOS may allow arbitrary code execution. This issue affects Zscaler Client Connector on MacOS prior to 4.2. |
| CVE-2024-23457 | Alta (7.8) | 0.20% | — | 1 may 2024 | The anti-tampering functionality of the Zscaler Client Connector can be disabled under certain conditions when an uninstall password is enforced. This affects Zscaler Client Connector on Windows prior to 4.2.0.209 |
| CVE-2024-23463 | Alta (8.1) | 0.37% | — | 30 abr 2024 | Anti-tampering protection of the Zscaler Client Connector can be bypassed under certain conditions when running the Repair App functionality. This affects Zscaler Client Connector on Windows prior to 4.2.1 |
| CVE-2024-23482 | Alta (7.8) | 0.27% | — | 26 mar 2024 | The ZScaler service is susceptible to a local privilege escalation vulnerability found in the ZScalerService process. Fixed Version: Mac ZApp 4.2.0.241 and later. |
| CVE-2023-41973 | Alta (7.8) | 0.31% | — | 26 mar 2024 | ZSATray passes the previousInstallerName as a config parameter to TrayManager, and TrayManager constructs the path and appends previousInstallerName to get the full path of the exe. Fixed Version: Win ZApp 4.3.0.121 and… |
| CVE-2023-41972 | Alta (7.8) | 0.24% | — | 26 mar 2024 | In some rare cases, there is a password type validation missing in Revert Password check and for some features it could be disabled. Fixed Version: Win ZApp 4.3.0.121 and later. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.