CVE-2026-59565
massRemote Buffer Overflow DoS in Zscaler Client Connector for Windows
Zscaler has disclosed a remotely exploitable buffer overflow in the Windows build of its Client Connector endpoint agent, tracked as CVE-2026-59565. Per the CVSS vector, an attacker with network reachability and low (authenticated) privileges, and without user interaction, can trigger the flaw, which corrupts memory in the affected component and can crash both the application and the Windows kernel, producing a local and kernel-level denial of service. While the advisory describes denial-of-service as the outcome, the CVSS 3.1 score of 8.8 (High) rates confidentiality, integrity, and availability impacts as high. Any organization running Zscaler Client Connector on Windows endpoints is affected; specific affected version ranges were not included in the available data and should be taken from Zscaler's advisory. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS estimates roughly a 0.3% chance of exploitation within 30 days.
What to do: Inventory Windows endpoints running Zscaler Client Connector and upgrade to the patched release specified in Zscaler's security advisory for CVE-2026-59565, since no affected/fixed version numbers are included in the data here. Because the flaw is remotely triggerable and can crash the Windows kernel, prioritize patching servers, kiosks, and other high-availability endpoints; no workaround is documented, and there is currently no known public PoC or in-the-wild exploitation to monitor for.
| Zscaler Client Connector (Windows) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A remotely exploitable buffer overflow bug can cause a local and kernel denial-of-service attack on affected versions of Zscaler Client Connector on Windows.
- Weakness
- CWE-229
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.