CVE-2024-23460: Zscaler Client Connector

High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.

The Zscaler Updater process does not validate the digital signature of the installer before execution, allowing arbitrary code to be locally executed. This affects Zscaler Client Connector on MacOS <4.2.

Affected products

  • Zscaler Client Connector: before 4.2 (fixed in 4.2)

Published 2024-08-06. Last modified 2026-06-17.