Known Vulnerabilities for products from Zscaler
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Zscaler".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-22569 json | An incorrect startup configuration of affected versions of Zscaler Client Connector on Windows may cause a limited amount of ... | Not Provided | 2026-03-31 | 2026-04-06 |
| CVE-2023-41717 json | Inappropriate file type control in Zscaler Proxy versions 3.6.1.25 and prior allows local attackers to bypass file download/u... | 5.5 - MEDIUM | 2023-08-31 | 2023-09-07 |
| CVE-2023-28805 json | An Improper Input Validation vulnerability in Zscaler Client Connector on Linux allows Privilege Escalation. This issue affec... | 9.8 - CRITICAL | 2023-10-23 | 2023-10-27 |
| CVE-2023-28804 json | An Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows replacing binar... | 5.3 - MEDIUM | 2023-10-23 | 2023-10-27 |
| CVE-2023-28803 json | An authentication bypass by spoofing of a device with a synthetic IP address is possible in Zscaler Client Connector on Windo... | 6.5 - MEDIUM | 2023-10-23 | 2023-10-27 |
| CVE-2023-28802 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 5.4 - MEDIUM | 2023-11-21 | 2023-11-29 |
| CVE-2023-28801 json | An Improper Verification of Cryptographic Signature in the SAML authentication of the Zscaler Admin UI allows a Privilege Esc... | 9.8 - CRITICAL | 2023-08-31 | 2023-09-07 |
| CVE-2023-28800 json | When using local accounts for administration, the redirect url parameter was not encoded correctly, allowing for an XSS attac... | 6.1 - MEDIUM | 2023-06-22 | 2023-06-30 |
| CVE-2023-28799 json | A URL parameter during login flow was vulnerable to injection. An attacker could insert a malicious domain in this parameter... | 6.1 - MEDIUM | 2023-06-22 | 2023-06-30 |
| CVE-2023-28797 json | Zscaler Client Connector for Windows before 4.1 writes/deletes a configuration file inside specific folders on the disk. A ma... | 7.3 - HIGH | 2023-10-23 | 2023-10-27 |
| CVE-2023-28796 json | Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows Code Injection. T... | 7.8 - HIGH | 2023-10-23 | 2023-10-27 |
| CVE-2023-28795 json | Origin Validation Error vulnerability in Zscaler Client Connector on Linux allows Inclusion of Code in Existing Process. This... | 7.8 - HIGH | 2023-10-23 | 2023-10-27 |
| CVE-2023-28794 json | Origin Validation Error vulnerability in Zscaler Client Connector on Linux allows Privilege Abuse. This issue affects Zscaler... | 6.5 - MEDIUM | 2023-11-06 | 2023-11-14 |
| CVE-2023-28793 json | Buffer overflow vulnerability in the signelf library used by Zscaler Client Connector on Linux allows Code Injection. This is... | 7.8 - HIGH | 2023-10-23 | 2023-10-27 |
| CVE-2021-26738 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 7.8 - HIGH | 2023-10-23 | 2023-10-27 |
| CVE-2021-26737 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 4.7 - MEDIUM | 2023-10-23 | 2023-10-27 |
| CVE-2021-26736 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 7.8 - HIGH | 2023-10-23 | 2023-10-27 |
| CVE-2021-26735 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 7.8 - HIGH | 2023-10-23 | 2023-10-27 |
| CVE-2021-26734 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 5.5 - MEDIUM | 2023-10-23 | 2023-10-27 |
| CVE-2020-11635 json | The Zscaler Client Connector prior to 3.1.0 did not sufficiently validate RPC clients, which allows a local adversary to exec... | 7.8 - HIGH | 2021-02-16 | 2021-07-21 |
Known software with vulnerabilities from Zscaler
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Zscaler | Client Connector | - |