ZeroHour

CVE-2026-25687

mass

Race Condition in Zscaler Client Connector ZPA Tunnel Handler Enables Heap Corruption

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-25687 is a race condition (CWE-366) in the ZPA tunnel handler of Zscaler Client Connector (ZCC) that can corrupt heap memory. The flaw is network-reachable with no privileges or user interaction required (CVSS 8.1), so a remote attacker able to deliver traffic processed concurrently by the tunnel handler — most relevant where Zscaler Private Access (ZPA) tunnels are in use — could crash the client (denial of service) or potentially execute arbitrary code in the context of the ZCC process. The high attack-complexity rating reflects the tight timing window typical of race conditions, which makes reliable code execution harder than a simple crash. Affected parties are organizations deploying ZCC on endpoint devices, especially those using ZPA. No public proof of concept is known and the CVE is not on CISA's KEV list, so there is currently no evidence of exploitation in the wild.

What to do: Update Zscaler Client Connector to the latest release once Zscaler's advisory identifies fixed builds, and verify that ZCC auto-update is enabled so endpoints pull the patch promptly. Inventory endpoint ZCC versions, prioritizing users who actively use Zscaler Private Access since the vulnerable ZPA tunnel handler is exercised in that mode. Monitor Zscaler's security bulletin and endpoint logs for unexplained ZCC crashes, which could indicate attempted exploitation.

Affected
Zscaler Client Connector (ZCC)
Estimated exposure
massTens of millions of endpoints (order of magnitude 10M+; Zscaler reports 40M+ protected users and ZCC is the standard agent on managed devices) — Zscaler publicly reports protecting tens of millions of users, and Client Connector is installed on essentially every managed endpoint in Zscaler Internet Access/Private Access deployments, implying a very large install base even if only a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A race condition in the ZPA tunnel handler of affected versions of Zscaler Client Connector (ZCC) allows a heap corruption, resulting in a denial of service (client crash) and potentially arbitrary code execution in the context of the ZCC process.

Weakness
CWE-366
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.