CVE-2026-59567
massLocal Privilege Escalation in Zscaler Client Connector
CVE-2026-59567 describes multiple vulnerabilities in affected versions of Zscaler Client Connector, the endpoint agent for Zscaler's Zero Trust services, that allow local privilege escalation (classified under CWE-280, improper handling of insufficient privileges). An unprivileged local user on a machine running an affected version can trigger the flaw with no user interaction and execute arbitrary code in a privileged context. Successful exploitation gives the attacker elevated-privilege code execution with high impact on confidentiality, integrity and availability (CVSS scope 'changed'), effectively enabling full compromise of the endpoint. Any organization running Zscaler Client Connector on workstations, laptops, or other endpoints with an affected version is exposed. No public proof-of-concept, KEV listing, or in-the-wild exploitation is currently known, and EPSS estimates only about a 0.1% probability of exploitation within 30 days.
What to do: Consult Zscaler's security advisory for CVE-2026-59567 and upgrade Client Connector to the fixed release it specifies (fixed version numbers are not included in the provided data). Verify deployed agent versions via your endpoint/management console and remediate broadly, prioritizing shared or multi-user endpoints and any hosts where untrusted local logon is possible, since exploitation requires local access. Because this is a local privilege escalation rather than a network-facing flaw, it is best treated as a hardening and patch-compliance issue rather than an urgent perimeter incident.
| Zscaler Client Connector | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving an unprivileged user the ability to execute arbitrary code in a privileged context.
- Weakness
- CWE-280
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.