Critical RCE Vulnerability in Zscaler Client Connector Exposes Enterprises to Remote Attacks
A critical remote code execution (RCE) vulnerability in Zscaler’s Client Connector endpoint application, tracked as CVE-2026-59568, has been disclosed, allowing unauthenticated attackers to execute arbitrary code without user interaction or credentials. The flaw, assigned a CVSS score of 9.1, is classified as critical due to its low attack complexity and network-based exploitability (CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
The vulnerability affects Zscaler Client Connector on Windows endpoints, posing a severe risk to enterprises using the software for proxying, traffic inspection, and security policy enforcement. Successful exploitation could compromise confidentiality and integrity, though no availability impact has been reported. Zscaler’s advisory indicates the flaw encompasses multiple RCE vulnerabilities rather than a single isolated issue.
Patches were released on June 1, 2026, with fixed versions including 4.8.0.232 and later builds (e.g., 4.9.0.455, 4.8.0.291). The same update cycle also addresses additional critical flaws:
- CVE-2026-59564 (authentication bypass)
- CVE-2026-59567 (local privilege escalation)
- CVE-2026-59565 (local/kernel denial-of-service)
Given the widespread use of Client Connector in Zscaler Internet Access and Private Access deployments, exploitation could grant attackers an initial foothold on managed endpoints, enabling credential theft, security control tampering, lateral movement, or data exfiltration. Security teams are advised to verify endpoint versions and monitor for suspicious activity, such as unexpected child processes or anomalous network connections. No public exploits have been reported, limiting detection options for defenders.
Source: https://cyberpress.org/critical-zscaler-client-connector-vulnerability/
Zscaler cybersecurity rating report: https://www.rankiteo.com/company/zscaler
"id": "ZSC1787660793",
"linkid": "zscaler",
"type": "Vulnerability",
"date": "6/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': 'Enterprises using Zscaler '
'Client Connector for Zscaler '
'Internet Access and Private '
'Access deployments',
'industry': 'Cybersecurity',
'name': 'Zscaler',
'type': 'Company'}],
'attack_vector': 'Network',
'customer_advisories': 'Security teams advised to verify endpoint versions '
'and monitor for suspicious activity.',
'data_breach': {'data_exfiltration': 'Potential data exfiltration'},
'date_publicly_disclosed': '2026-06-01',
'date_resolved': '2026-06-01',
'description': 'A critical remote code execution (RCE) vulnerability in '
'Zscaler’s Client Connector endpoint application, tracked as '
'CVE-2026-59568, has been disclosed, allowing unauthenticated '
'attackers to execute arbitrary code without user interaction '
'or credentials. The flaw affects Zscaler Client Connector on '
'Windows endpoints, posing a severe risk to enterprises using '
'the software for proxying, traffic inspection, and security '
'policy enforcement. Successful exploitation could compromise '
'confidentiality and integrity. Zscaler’s advisory indicates '
'the flaw encompasses multiple RCE vulnerabilities.',
'impact': {'data_compromised': 'Confidentiality and integrity of enterprise '
'data',
'operational_impact': 'Potential credential theft, security '
'control tampering, lateral movement, or '
'data exfiltration',
'systems_affected': 'Windows endpoints running Zscaler Client '
'Connector'},
'post_incident_analysis': {'corrective_actions': 'Patches released and '
'applied',
'root_causes': 'Critical RCE vulnerability in '
'Zscaler Client Connector '
'(CVE-2026-59568)'},
'recommendations': 'Verify endpoint versions, monitor for suspicious '
'activity, and apply patches immediately.',
'references': [{'source': 'Zscaler Advisory'}],
'response': {'communication_strategy': 'Security advisory issued',
'containment_measures': 'Patches released (versions 4.8.0.232 '
'and later)',
'enhanced_monitoring': 'Monitor for suspicious activity (e.g., '
'unexpected child processes, anomalous '
'network connections)',
'remediation_measures': 'Update to fixed versions (e.g., '
'4.9.0.455, 4.8.0.291)'},
'title': 'Critical RCE Vulnerability in Zscaler Client Connector Exposes '
'Enterprises to Remote Attacks',
'type': 'Remote Code Execution (RCE)',
'vulnerability_exploited': 'CVE-2026-59568, CVE-2026-59564, CVE-2026-59567, '
'CVE-2026-59565'}