Multiple Zscaler Client Connector Flaws Enable Remote Code Execution (CVE-2026-59568) — Threadlinqs Intelligence
As of 2026-08-25, Multiple Zscaler Client Connector Flaws Enable Remote Code Execution (CVE-2026-59568) is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 18 indicators of compromise.
Threat ID: TL-2026-2139 · Severity: CRITICAL · CVSS: 9.1 · Status: ACTIVE · Category: VULNERABILITY
Zscaler patched five vulnerabilities in Client Connector in its June 1, 2026 release train, headlined by CVE-2026-59568 (CVSS 9.1, CWE-20), which lets an unauthenticated, unprivileged attacker execute
Zscaler Client Connector — the endpoint agent that brokers Zero Trust/SASE connectivity for Zscaler Internet Access and Private Access — shipped five CVEs in the same 2026 release train, disclosed via Zscaler's Client Connector App Release Summary 2026 and published to NVD on 2026-08-24.
CVE-2026-59568 is the headline issue: an improper-input-validation flaw (CWE-20) that allows an unauthenticated, unprivileged attacker to execute arbitrary code within the Client Connector's own process context (CVSS 3.1 9.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). NVD's description frames it as 'multiple vulnerabilities' rather than a single bug, indicating more than one distinct code path reaches the unvalidated-input condition.
CVE-2026-59564 is a CWE-304 (Missing Critical Step in Authentication) issue in the communications channel between the Client Connector app and its backend Client Connector Portal, also scored 9.1 with an identical vector — meaning an attacker on the network path between agent and portal can bypass an authentication step in that protocol.
CVE-2026-59567 is a set of local privilege-escalation bugs (CWE-280, Improper Handling of Insufficient Permissions or Privileges, CVSS 8.8: AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) letting an unprivileged local user reach arbitrary code execution in a privileged context; the Scope:Changed (S:C) vector confirms the exploited component's privileges extend beyond its own security scope.
CVE-2026-59565 is a remotely reachable buffer overflow (CWE-229, Improper Handling of Values, CVSS 8.8: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) that crashes the Windows kernel/driver component, producing a local and kernel denial-of-service condition.
Fixed builds were published across Windows, macOS, Linux, Android, ChromeOS, and iOS on 2026-06-01, roughly 12 weeks before the CVEs were assigned and publicized; GBHackers additionally cites a further round of Windows hardening builds (4.9.0.455, 4.8.0.291, 4.9.0.448, 4.8.0.284, 4.7.0.364) beyond the initial June baseline. As of the 2026-08-25 GBHackers report, no public proof-of-concept, technical exploit writeup, or exploitation-in-the-wild has surfaced, and this research found no additional public PoC or KEV listing. Because Client Connector is a widely deployed enterprise security/VPN agent that typically runs with elevated (SYSTEM/service) privileges, unpatched fleets remain a high-value target: compromising the agent itself both grants code execution on the endpoint and can undermine the security control the agent is meant to provide.
A fifth vulnerability in the same release train, CVE-2026-59566 (CVSS 3.1: 8.4, AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, CWE-229), was published alongside the other four on 2026-08-24: a locally exploitable buffer overflow causing a local denial-of-service on Android and ChromeOS builds prior to 4.2, sharing the same weakness class (Improper Handling of Values) as the Windows kernel DoS in CVE-2026-59565. Together the five CVEs span every platform Client Connector ships on (Windows, macOS, Linux, Android, ChromeOS, iOS) and give this release train an average disclosed CVSS in the high-8s/low-9s range — a marked jump from an earlier, unrelated 2026 Client Connector issue this research also located (CVE-2026-22569, CVSS 5.4, published 2026-03-31), where an incorrect startup configuration on Windows could leave a limited amount of traffic uninspected under rare circumstances. Tenable's legacy CVSSv2 scoring for CVE-2026-59568 (9.4, AV:N/AC:L/Au:N/C:C/I:C/A:N) corroborates the same complete-confidentiality/integrity-compromise characterization as the v3.1 score.
Two evidence-bound technical inferences follow from the published CVSS vectors even though Zscaler has not disclosed the vulnerable component, listening port, or protocol for any of the five CVEs. First, CVE-2026-59565's vector carries PR:L despite an AV:N (network) attack vector — meaning, per Tenable's own phrasing, the flaw requires an 'authenticated remote attacker,'
Weaknesses (CWE)
CWE-20, CWE-304, CWE-280, CWE-229
Timeline
- Zscaler discloses an earlier, unrelated Windows Client Connector issue, CVE-2026-22569 (CVSS 5.4, improper validation of unsafe equivalence in input), where an incorrect startup configuration could leave a limited amount of traffic uninspected under rare circumstances — part of a broader pattern of Client Connector vulnerabilities disclosed across 2026.
- Zscaler ships remediated Client Connector builds (e.g., Windows 4.8.0.232, Android/ChromeOS 4.2) later confirmed to fix CVE-2026-59568, CVE-2026-59564, CVE-2026-59567, CVE-2026-59565, and CVE-2026-59566.
- NVD publishes CVE-2026-59568 (CVSS 9.1 RCE, CWE-20), CVE-2026-59564 (CVSS 9.1 auth bypass, CWE-304), CVE-2026-59567 (CVSS 8.8 local privilege escalation, CWE-280), and CVE-2026-59565 (CVSS 8.8 local/kernel DoS, CWE-229) for Zscaler Client Connector.
- NVD separately publishes a fifth Client Connector vulnerability in the same disclosure batch, CVE-2026-59566 (CVSS 8.4, CWE-229 buffer overflow), producing a local denial-of-service on Android and ChromeOS builds prior to 4.2 — bringing the June 2026 release train to five total CVEs.
- Zscaler's Client Connector App Release Summary 2026 documents all five vulnerabilities and the remediated version numbers across Windows, macOS, Linux, Android, ChromeOS, and iOS.
- GBHackers publishes coverage of the four headline vulnerabilities, stating that public technical exploit details and reliable IOCs are not yet available and that no active exploitation is confirmed.
- TL-Intel research confirms no public proof-of-concept, exploit code, PoC-tracker listing, or CISA KEV entry exists for any of the five CVEs as of this report; Zscaler has not disclosed the specific affected component, port, or protocol for any of the flaws.
- TL-Intel pipeline ingests the GBHackers report via RSS hunt and opens threat tracking for TL-2026-2139.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 18 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-59568, CVE-2026-59564, CVE-2026-59567, CVE-2026-59565, CVE-2026-59566, T1595.002, T1588.006, T1588.005, T1203, T1557, T1556, T1499.004, T1489