CVE-2026-25687
massRace Condition in Zscaler Client Connector ZPA Tunnel Handler Enables Heap Corruption
CVE-2026-25687 is a race condition (CWE-366) in the ZPA tunnel handler of Zscaler Client Connector (ZCC) that can corrupt heap memory. The flaw is network-reachable with no privileges or user interaction required (CVSS 8.1), so a remote attacker able to deliver traffic processed concurrently by the tunnel handler — most relevant where Zscaler Private Access (ZPA) tunnels are in use — could crash the client (denial of service) or potentially execute arbitrary code in the context of the ZCC process. The high attack-complexity rating reflects the tight timing window typical of race conditions, which makes reliable code execution harder than a simple crash. Affected parties are organizations deploying ZCC on endpoint devices, especially those using ZPA. No public proof of concept is known and the CVE is not on CISA's KEV list, so there is currently no evidence of exploitation in the wild.
What to do: Update Zscaler Client Connector to the latest release once Zscaler's advisory identifies fixed builds, and verify that ZCC auto-update is enabled so endpoints pull the patch promptly. Inventory endpoint ZCC versions, prioritizing users who actively use Zscaler Private Access since the vulnerable ZPA tunnel handler is exercised in that mode. Monitor Zscaler's security bulletin and endpoint logs for unexplained ZCC crashes, which could indicate attempted exploitation.
| Zscaler Client Connector (ZCC) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A race condition in the ZPA tunnel handler of affected versions of Zscaler Client Connector (ZCC) allows a heap corruption, resulting in a denial of service (client crash) and potentially arbitrary code execution in the context of the ZCC process.
- Weakness
- CWE-366
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.