CVE-2026-59570: Android ZCC denial of service
Published Sep 14, 2026
·Updated
On affected versions of Zscaler client connector, a pre-installed peer app can tear down the Zscaler tunnel, force user logout, and toggle packet capture.
Affected Software
1 affected component
Zscaler Client Connector
Event History
Sep 14, 2026
CVE Published
via MITRE·02:47 PM
Data Sourced
via MITRE·02:47 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which devices are exposed to this issue?
Android devices running an affected version of Zscaler Client Connector are exposed when a peer app is already installed on the device.
2
What level of access does an attacker need?
An attacker needs control of a pre-installed peer app and requires low privileges. The issue is locally exploitable and does not require user interaction.
3
What can a successful exploit do?
A malicious peer app can tear down the Zscaler tunnel, force the user to log out, and toggle packet capture. This can affect integrity and availability.