CVE-2026-25687: Zscaler Client Connector
High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.
A race condition in the ZPA tunnel handler of affected versions of Zscaler Client Connector (ZCC) allows a heap corruption, resulting in a denial of service (client crash) and potentially arbitrary code execution in the context of the ZCC process.
Affected products
- Zscaler Client Connector: from 4.6, before 4.6.0.486 (fixed in 4.6.0.486); from 4.7, before 4.7.0.350 (fixed in 4.7.0.350); from 4.8, before 4.8.0.267 (fixed in 4.8.0.267); from 4.9, before 4.9.0.412 (fixed in 4.9.0.412)
Published 2026-09-14. Last modified 2026-09-18.