CVE-2026-59568
massUnauthenticated RCE in Zscaler Client Connector (multiple input-validation flaws)
CVE-2026-59568, assigned by Zscaler, bundles multiple input-validation flaws (CWE-20) in the Zscaler Client Connector (ZCC) endpoint agent that allow an unauthenticated, unprivileged user to execute arbitrary code in the context of the ZCC process. The CVSS vector rates the attack as network-exploitable (AV:N) with low complexity and no privileges, user interaction, or scope change, producing high confidentiality and integrity impact and no availability impact. Successful exploitation gives an attacker code execution inside the Client Connector agent — the privileged component that mediates a device's zero-trust connectivity to Zscaler — on any endpoint running an affected version. All organizations deploying ZCC on user devices are in scope; the source data does not enumerate specific affected or fixed version ranges, which must be taken from Zscaler's advisory. No public proof-of-concept, CISA KEV listing, or in-the-wild exploitation is known, and EPSS estimates only about a 0.4% probability of exploitation within 30 days (31st percentile).
What to do: Inventory all managed endpoints for Zscaler Client Connector and upgrade to the fixed release named in Zscaler's security advisory, since this CVE aggregates multiple flaws and the current fixed build addresses all of them. Verify installed agent versions via your endpoint-management tooling because version ranges are not enumerated in the available data. With no public PoC or in-the-wild exploitation known, treat this as an expedited high-priority (CVSS 9.1) patch rather than an emergency response.
| Zscaler Client Connector (ZCC) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context.
- Weakness
- CWE-20
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.