Race Condition Vulnerability in Zscaler Client Connector
CVE-2026-25687
8.1HIGH
What is CVE-2026-25687?
A race condition in the Zscaler Client Connector's tunnel handler can lead to heap corruption, causing a denial of service where the client may crash. This vulnerability poses a risk of arbitrary code execution in the context of the Zscaler Client Connector process, potentially allowing attackers to execute malicious actions.
Affected Version(s)
Client Connector Windows 4.6 < 4.6.0.486
Client Connector Windows 4.7 < 4.7.0.350
Client Connector Windows 4.8 < 4.8.0.267
