CVE-2025-54983: Zscaler Client Connector

Medium severity, CVSS 5.2. EPSS: 0.1% chance of exploitation in the next 30 days.

A health check port on Zscaler Client Connector on Windows, versions 4.6 < 4.6.0.216 and 4.7 < 4.7.0.47, which under specific circumstances was not released after use, allowed traffic to potentially bypass ZCC forwarding controls.

Affected products

  • Zscaler Zscaler Client Connector: from 4.6, before 4.6.0.216 (fixed in 4.6.0.216); from 4.7, before 4.7.0.47 (fixed in 4.7.0.47)

Published 2025-11-12. Last modified 2026-06-17.