CVE-2026-25684: File Type Control rule bypass
Published Sep 18, 2026
·Updated
A file type attribution issue in Zscaler Internet Access File Type Control evaluation rules may allow improper evaluation of File Type Control policies in rare circumstances.
Affected Software
1 affected component
Zscaler Zscaler Internet Access File Type Control evaluation rules
Event History
Sep 18, 2026
CVE Published
via MITRE·02:01 PM
Data Sourced
via MITRE·02:01 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access and conditions does an attacker need to exploit this issue?
Exploitation requires network access, low-level privileges, and user interaction. The attack complexity is high, and the issue occurs only in rare circumstances.
2
What is the potential impact if exploitation succeeds?
The vulnerability may cause File Type Control policies to be evaluated improperly. It can result in limited confidentiality and integrity impact, with no stated availability impact.