{"record":"Zscaler evidence record","url":"https://nexalign.io/vendors/zscaler","vendor":{"slug":"zscaler","name":"Zscaler","domain":"zscaler.com","category":"network","categoryLabel":"Network security"},"lastChecked":"2026-07-17T22:22:49.502Z","coverage":{"earliest":"2023-06-22T19:06:24.000Z","latest":"2026-07-17T22:22:49.502Z"},"terms":{"isRanking":false,"isRating":false,"statesSuitability":false,"note":"This is a record of what public sources hold about a named company. It states no ranking, no rating and no suitability verdict, and none may be derived from it. An absent or small record means the public registers publish little under that name; it is not evidence that a product is secure. A larger advisory count generally reflects wider deployment and more scrutiny rather than a weaker product.","licence":"https://nexalign.io/vendors#licence","corrections":"info@nexalign.io"},"totals":{"evidenceItems":45,"kindsOfSource":4,"attributedAdvisories":36,"knownExploited":0,"registerEntriesNotAttributable":1,"practitionerThreads":1,"independentItems":6,"vendorPublishedItems":0,"shareFromSourcesTheVendorDoesNotControl":1},"sources":[{"source":"European Vulnerability Database","operator":"ENISA, European Union","classification":"authoritative","items":25,"latest":"2026-03-31T14:54:57.000Z"},{"source":"CERT-Bund security advisories","operator":"BSI, Federal Republic of Germany","classification":"authoritative","items":12,"latest":"2026-04-01T10:23:58.213Z"},{"source":"Analyst, review and reference sources","operator":"Recognised analysts, review marketplaces and technology press","classification":"independent","items":6,"latest":"2026-07-17T22:22:49.502Z"},{"source":"Engineering discussions","operator":"Hacker News, public threads","classification":"independent","items":2,"latest":"2026-02-15T10:50:18.000Z"}],"advisories":{"shown":6,"total":36,"truncated":true,"fullList":"https://nexalign.io/vendors/zscaler/advisories","items":[{"id":"WID-SEC-2026-0938","description":"Affected products: ZScaler Client Connector","severity":"medium","cvss":5.4,"knownExploited":false,"date":"2026-04-01T10:23:58.213Z","sources":["https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-0938"]},{"id":"CVE-2026-22569","description":"An incorrect startup configuration of affected versions of Zscaler Client Connector on Windows may cause a limited amount of traffic from being inspected under rare circumstances.","severity":"medium","cvss":5.4,"knownExploited":false,"date":"2026-03-31T14:54:57.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-17478"]},{"id":"CVE-2026-22567","description":"Improper validation of user-supplied input in the ZIA Admin UI could allow an authenticated administrator to initiate backend functions through specific input fields in limited scenarios.","severity":"high","cvss":7.6,"knownExploited":false,"date":"2026-02-23T16:13:32.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-7563"]},{"id":"CVE-2026-22568","description":"Improper neutralization of special elements in user-supplied input within the ZIA Admin UI could allow an authenticated administrator to access or retrieve unauthorized internal information…","severity":"medium","cvss":5.5,"knownExploited":false,"date":"2026-02-23T16:12:52.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-7559"]},{"id":"WID-SEC-2025-2578","description":"Affected products: ZScaler Client Connector","severity":"medium","cvss":5.2,"knownExploited":false,"date":"2025-11-12T11:22:16.705Z","sources":["https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-2578"]},{"id":"CVE-2025-54983","description":"A health check port on Zscaler Client Connector on Windows, versions 4.6 <  4.6.0.216 and 4.7 < 4.7.0.47, which under specific circumstances was not released after use, allowed traffic to…","severity":"medium","cvss":5.2,"knownExploited":false,"date":"2025-11-12T03:07:39.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-119999"]}]},"practitionerThreads":{"shown":1,"total":1,"truncated":false,"items":[{"title":"Show HN: Pangolin: Open-source identity-based VPN (Twingate/Zscaler alternative)","context":"Hacker News","url":"https://news.ycombinator.com/item?id=47022745","date":"2026-02-15T10:50:18.000Z"}]},"independentCoverage":{"shown":5,"total":6,"truncated":true,"items":[{"title":"Zscaler - Wikipedia","host":"en.wikipedia.org","url":"https://en.wikipedia.org/wiki/Zscaler","date":null},{"title":"Zscaler Platform Reviews & Ratings 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/product/zscaler-platform","date":null},{"title":"Zscaler Zero Trust SASE Reviews & Ratings 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/product/zscaler-zero-trust-sase","date":null},{"title":"Zscaler Reviews, Ratings & Features 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/market/security-service-edge/vendor/zscaler","date":null},{"title":"What is your primary use case for Zscaler Private Access? | PeerSpot","host":"peerspot.com","url":"https://www.peerspot.com/questions/what-is-your-primary-use-case-for-zscaler-private-access","date":null}]},"vendorPublished":{"shown":0,"total":0,"truncated":false,"items":[]},"openQuestions":["A further 1 register entries mention Zscaler without naming a product of Zscaler as affected. They are excluded rather than counted as vulnerabilities.","Pricing, contract terms, notice periods and support commitments are not part of any public register. They come from the vendor and belong in a negotiation record.","Certification status such as ISO 27001, SOC 2 or BSI C5 has to be checked against the current certificate and its stated scope. A valid certificate can still exclude the product being bought."]}