CVE-2026-59568: Remote Code Execution
Published Aug 24, 2026
·Updated
Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context.
Affected Software
1 affected component
Zscaler Zscaler Client Connector
Event History
Aug 24, 2026
CVE Published
via MITRE·01:44 PM
Data Sourced
via MITRE·01:44 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
An attacker does not need to authenticate or hold any privileges. The attack vector is network-based and requires no user interaction.
2
What could an attacker do after successful exploitation?
Successful exploitation allows arbitrary code execution in the Zscaler Client Connector context. The vulnerability affects confidentiality and integrity at a high impact level.