Network security
Zscaler advisories: every record the registers tie to its products
In one line
36 advisories are attributed to Zscaler products in this record, covering June 2023 to April 2026, and none of them appears in the CISA catalogue of known exploited vulnerabilities. A further 1 register entry mentions Zscaler without naming one of its products as affected, and is excluded rather than counted. Each entry below links to the register that published it.
Attributed
36
tied to a named product
Known exploited
0
in the CISA catalogue
Rated critical
2
by the register
Last checked
Jul 17, 2026
sources re-queried
Why this list is shorter than a CVE mirror
The registers are searched by keyword, so a search for a company name returns advisories that merely mention it. A mirror publishes those. This page does not: an entry appears only when the register itself ties it to a product of Zscaler, through a reference on the vendor's own domain, the vendor named as the assigning authority, or the affected product list naming it.
1 entry did not clear that bar and is not shown. That is the difference, and it is deliberate: a page that lists another company's vulnerability under this heading is wrong in the way that matters most.
36 of the 36 records carry a CVSS base score from the register. Where none is published, none is shown, and no score is estimated.
The full list, most recently exploited and most recent first
Records held by several registers are folded into one entry with a link to each, so the same vulnerability is not counted twice. Entries listed in the CISA catalogue of known exploited vulnerabilities are shown first, because that is the one flag on this page that changes what a reader should do next.
- WID-SEC-2026-0938mediumCVSS 5.4Apr 01, 2026
Affected products: ZScaler Client Connector
- CVE-2026-22569mediumCVSS 5.4Mar 31, 2026
An incorrect startup configuration of affected versions of Zscaler Client Connector on Windows may cause a limited amount of traffic from being inspected under rare circumstances.
- CVE-2026-22567highCVSS 7.6Feb 23, 2026
Improper validation of user-supplied input in the ZIA Admin UI could allow an authenticated administrator to initiate backend functions through specific input fields in limited scenarios.
- CVE-2026-22568mediumCVSS 5.5Feb 23, 2026
Improper neutralization of special elements in user-supplied input within the ZIA Admin UI could allow an authenticated administrator to access or retrieve unauthorized internal information…
- WID-SEC-2025-2578mediumCVSS 5.2Nov 12, 2025
Affected products: ZScaler Client Connector
- CVE-2025-54983mediumCVSS 5.2Nov 12, 2025
A health check port on Zscaler Client Connector on Windows, versions 4.6 < 4.6.0.216 and 4.7 < 4.7.0.47, which under specific circumstances was not released after use, allowed traffic to…
- CVE-2025-54982criticalCVSS 9.6Aug 05, 2025
An improper verification of cryptographic signature in Zscaler's SAML authentication mechanism on the server-side allowed an authentication abuse.
- WID-SEC-2025-1229mediumCVSS 7.3Jun 04, 2025
Affected products: ZScaler Client Connector
- CVE-2024-31127highCVSS 7.3Jun 04, 2025
An improper verification of a loaded library in Zscaler Client Connector on Mac < 4.2.0.241 may allow a local attacker to elevate their privileges.
- WID-SEC-2024-0729mediumCVSS 7.3Nov 19, 2024
Affected products: ZScaler Client Connector
- WID-SEC-2024-1779mediumCVSS 7.8Aug 07, 2024
Affected products: ZScaler Client Connector
- WID-SEC-2024-1014mediumCVSS 7.1May 03, 2024
Affected products: ZScaler Client Connector
- WID-SEC-2024-1000mediumCVSS 7.5May 02, 2024
Affected products: ZScaler Client Connector
- WID-SEC-2024-0998highCVSS 8.8May 02, 2024
Affected products: ZScaler Client Connector
- CVE-2023-41972highCVSS 7.3Mar 26, 2024
In some rare cases, there is a password type validation missing in Revert Password check and for some features it could be disabled.
- CVE-2023-41969highCVSS 7.3Mar 26, 2024
An arbitrary file deletion in ZSATrayManager where it protects the temporary encrypted ZApp issue reporting file from the unprivileged end user access and modification.
- CVE-2023-28807mediumCVSS 5.1Jan 31, 2024
In Zscaler Internet Access (ZIA) a mismatch between Connect Host and Client Hello's Server Name Indication (SNI) enables attackers to evade network security controls by hiding their…
- WID-SEC-2023-2988mediumCVSS 4.9Nov 22, 2023
Affected products: ZScaler Client Connector
- CVE-2023-28802mediumCVSS 4.9Nov 21, 2023
An Improper Validation of Integrity Check Value in Zscaler Client Connector on Windows allows an authenticated user to disable ZIA/ZPA by interrupting the service restart from Zscaler…
- WID-SEC-2023-2831lowCVSS 4.3Nov 06, 2023
Affected products: ZScaler Client Connector
- WID-SEC-2023-2733highCVSS 8.2Oct 24, 2023
Affected products: ZScaler Client Connector
- CVE-2023-28805mediumCVSS 6.7Oct 23, 2023
An Improper Input Validation vulnerability in Zscaler Client Connector on Linux allows Privilege Escalation.
- CVE-2023-28804highCVSS 8.2Oct 23, 2023
An Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows replacing binaries.This issue affects Linux Client Connector: before 1.4.0.105
- CVE-2023-28797mediumCVSS 6.3Oct 23, 2023
Zscaler Client Connector for Windows before 4.1 writes/deletes a configuration file inside specific folders on the disk.
- CVE-2023-28796highCVSS 7.1Oct 23, 2023
Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows Code Injection.
- CVE-2023-28795highCVSS 7.8Oct 23, 2023
Origin Validation Error vulnerability in Zscaler Client Connector on Linux allows Inclusion of Code in Existing Process.
- CVE-2023-28793highCVSS 7.8Oct 23, 2023
Buffer overflow vulnerability in the signelf library used by Zscaler Client Connector on Linux allows Code Injection.
- CVE-2021-26738highCVSS 7.8Oct 23, 2023
Zscaler Client Connector for macOS prior to 3.7 had an unquoted search path vulnerability via the PATH variable.
- CVE-2021-26737mediumCVSS 5.5Oct 23, 2023
The Zscaler Client Connector for macOS prior to 3.6 did not sufficiently validate RPC clients.
- CVE-2021-26736mediumCVSS 6.7Oct 23, 2023
Multiple vulnerabilities in the Zscaler Client Connector Installer and Uninstaller for Windows prior to 3.6 allowed execution of binaries from a low privileged path.
- CVE-2021-26735mediumCVSS 6.7Oct 23, 2023
The Zscaler Client Connector Installer and Unsintallers for Windows prior to 3.6 had an unquoted search path vulnerability.
- CVE-2021-26734mediumCVSS 4.4Oct 23, 2023
Zscaler Client Connector Installer on Windows before version 3.4.0.124 improperly handled directory junctions during uninstallation.
- CVE-2023-28801criticalCVSS 9.6Aug 31, 2023
An Improper Verification of Cryptographic Signature in the SAML authentication of the Zscaler Admin UI allows a Privilege Escalation.This issue affects Admin UI: from 6.2 before 6.2r.
- WID-SEC-2023-1616mediumCVSS 6.1Jul 03, 2023
Affected products: ZScaler Client Connector
- CVE-2023-28800highCVSS 8.1Jun 22, 2023
When using local accounts for administration, the redirect url parameter was not encoded correctly, allowing for an XSS attack providing admin login.
- CVE-2023-28799highCVSS 8.2Jun 22, 2023
A URL parameter during login flow was vulnerable to injection.
Which registers contributed
| Register | Operated by | Entries | Latest |
|---|---|---|---|
| European Vulnerability Database | ENISA, European Union | 25 | Mar 31, 2026 |
| CERT-Bund security advisories | BSI, Federal Republic of Germany | 12 | Apr 01, 2026 |
The entry counts here are the raw register totals for Zscaler, before attribution. They are larger than the list above for exactly that reason.
Questions this page answers
How many vulnerabilities does Zscaler have?
36 advisories in this record are tied by a register to a product of Zscaler. That is not the same as the number of vulnerabilities the products contain, and no public source knows that number. It is the count of what has been found, disclosed and published, which depends on how much the products are examined and how openly the vendor discloses.
Are any Zscaler vulnerabilities being actively exploited?
None of the 36 records here appears in the CISA catalogue of known exploited vulnerabilities. That catalogue is not exhaustive: it lists what CISA has confirmed as exploited, so absence from it is not proof that nothing has been exploited.
Why does this page show fewer CVEs for Zscaler than other sites?
Because a keyword search for a company name returns advisories about other companies' products that mention it in passing, and this page excludes those. 1 register entry names Zscaler without naming one of its products as affected. A mirror that lists them produces a longer page and a wrong number.
Where do the Zscaler advisories on this page come from?
From European Vulnerability Database (ENISA, European Union); CERT-Bund security advisories (BSI, Federal Republic of Germany). Every entry links back to the register that published it, and carries the date that register states. Where the same vulnerability is held by several registers it is shown once with a link to each, rather than counted twice.
Does a long advisory list mean Zscaler is insecure?
No. A register records what researchers found and what the vendor disclosed, so a widely deployed product with a working disclosure process accumulates more entries than one nobody examines. A short list can equally mean a small install base or a vendor that publishes little. This page reports the record and does not rate the vendor, because whether this is acceptable depends on your risk appetite, your compliance scope and the alternatives you are weighing.
A list of advisories is not a risk assessment
What matters is which of these touch the components you actually run, in the configuration you actually run them in, and whether that is acceptable next to the alternatives on your shortlist. DecisionOS reads the same pool against the criteria of a real decision and produces a memo that holds up in front of a board and an auditor.
The full Zscaler record, including sources and open questions
