Client Connector vulnerability

A race condition in the ZPA tunnel handler of affected versions of Zscaler Client Connector (ZCC) allows a heap corruption, resulting in a denial of service (client crash) and potentially arbitrary code execution in the context of the ZCC process.

Published 14 Sep 2026Updated 15 Sep 20261 sources
CVSS 8.1

Source timeline

CVE record published by NVDView source ↗