Authentication Bypass in Zscaler Client Connector and Portal
CVE-2026-59564

9.1CRITICAL

Key Information:

Vendor

Zscaler

Vendor
CVE Published:
24 August 2026

What is CVE-2026-59564?

An authentication bypass vulnerability has been identified in the Zscaler Client Connector and its communication with the Zscaler Client Connector Portal. This flaw could potentially allow unauthorized access, compromising the integrity of user sessions and sensitive data. Users should ensure they are using the latest version of the Zscaler Client Connector to mitigate potential risks and enhance their security posture.

Affected Version(s)

Client Connector Windows 0

Client Connector Windows 0

Client Connector Windows 0

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.