CVE-2026-25687: ZCC race condition in ZPA tunnel handler
Published Sep 14, 2026
·Updated
A race condition in the ZPA tunnel handler of affected versions of Zscaler Client Connector (ZCC) allows a heap corruption, resulting in a denial of service (client crash) and potentially arbitrary code execution in the context of the ZCC process.
Affected Software
1 affected component
Zscaler Zscaler Client Connector (ZCC)
Event History
Sep 14, 2026
CVE Published
via MITRE·02:37 PM
Data Sourced
via MITRE·02:37 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The vulnerability is remotely reachable and requires no privileges or user interaction, according to the supplied CVSS vector. Exploitation has high attack complexity.
2
What is the potential impact if exploitation succeeds?
A successful race condition can corrupt heap memory in the ZPA tunnel handler, causing the client to crash. It may also permit arbitrary code execution in the context of the ZCC process, with high confidentiality, integrity, and availability impact.