CVE-2023-28807: Zscaler Secure Internet And Saas Access

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

In Zscaler Internet Access (ZIA) a mismatch between Connect Host and Client Hello's Server Name Indication (SNI) enables attackers to evade network security controls by hiding their communications within legitimate traffic.

Affected products

  • Zscaler Secure Internet And Saas Access: before 6.2r.290 (fixed in 6.2r.290)

Published 2024-01-31. Last modified 2026-06-17.