Zscaler has addressed several vulnerabilities in its Client Connector endpoint application that could allow an unauthenticated, unprivileged attacker to execute arbitrary code within the product’s context.
This vulnerability, tracked as CVE-2026-59568, is rated as Critical, with a CVSS v3.1 score of 9.1. The attack vector is network-accessible and requires no privileges or user interaction.
Multiple Zscaler Client Connector Flaws
The vulnerability was published on August 24, 2026. Zscaler’s release documentation indicates that CVE-2026-59568 mitigates multiple remote code execution (RCE) flaws, rather than being an isolated issue.
The National Vulnerability Database (NVD) categorizes it under CWE-20, which refers to improper input validation. The vendor has not publicly detailed the affected components, the sequence of exploitation, or whether active exploitation has been observed.
According to the CVSS vector, successful exploitation could compromise both confidentiality and integrity, while availability is not considered affected. The vulnerability is characterized as AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N, indicating a low-complexity attack path accessible via a network connection.
For enterprises deploying Client Connector as part of Zscaler Internet Access or Zscaler Private Access architectures, this finding is particularly important since endpoint connectivity software often operates with extensive access to network, proxy, tunnel, and posture-control functions.
Zscaler included the necessary fixes in its Client Connector releases on June 1, 2026. The Windows release notes state that version 4.8.0.232 mitigates the multiple RCE vulnerabilities associated with CVE-2026-59568.
Additionally, this release addresses an authentication bypass vulnerability tracked as CVE-2026-59564, multiple local privilege escalation issues labeled as CVE-2026-59567, and a local and kernel denial-of-service vulnerability identified as CVE-2026-59565.
Subsequent Windows versions listed in the 2026 release summary include 4.9.0.455, 4.8.0.291, 4.9.0.448, 4.8.0.284, and 4.7.0.364.
Administrators should verify their deployed build against Zscaler’s current release guidance and upgrade path, rather than assuming that the latest version installed through an existing endpoint management policy is fully remediated.
The risk extends beyond the immediate execution of attacker-supplied code. A compromised connector process could provide an adversary with a foothold on a managed endpoint, potentially enabling access to credentials, tampering with security controls, lateral movement, or data collection, depending on the process’s privileges and the surrounding endpoint protections.
Organizations should prioritize inventorying Windows endpoints running Zscaler Client Connector, identify any builds older than the vendor’s remediated releases, and expedite testing and rollout through their software distribution platform.
Security teams should also review endpoint telemetry for unusual child processes, unexpected network listeners, anomalous service activity, and modifications involving Zscaler components.
Since public technical details remain limited, network detection signatures and reliable indicators of compromise are currently unavailable from the disclosed advisory material.
Teams should focus on patch verification, reducing exposure, monitoring endpoints, and maintaining communication with the vendor.
Administrators should retain installation and upgrade logs, confirm successful deployments after reboot where applicable, and investigate systems where Client Connector updates failed or left the application partially installed.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC





