
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25687 is a race condition vulnerability in the ZPA tunnel handler of Zscaler Client Connector (ZCC) that can lead to heap corruption, resulting in denial of service (client crash) and potentially arbitrary code execution within the ZCC process context. It was published on September 14, 2026, and assigned a CVSS v3.1 base score of 8.1 (High) (Github Advisory). Affected versions span the 4.6, 4.7, 4.8, and 4.9 release branches of Zscaler Client Connector, specifically versions prior to 4.6.0.486, 4.7.0.350, 4.8.0.267, and 4.9.0.412 respectively (Github Advisory).
The vulnerability is classified as CWE-366 (Race Condition within a Thread), where two concurrent threads of execution access a shared resource simultaneously, leading to an undefined execution state and heap corruption in the ZPA tunnel handler component. An unauthenticated remote attacker can exploit this race condition over the network without requiring user interaction, though the high attack complexity (AC:H) indicates that exploitation requires precise timing or specific conditions to win the race (Github Advisory). The attack maps to CAPEC-26 (Leveraging Race Conditions) and CAPEC-29 (Leveraging Time-of-Check and Time-of-Use Race Conditions), suggesting the attacker must carefully time malicious requests to the ZPA tunnel handler to corrupt heap memory (Github Advisory).
Successful exploitation can result in a denial of service through a crash of the Zscaler Client Connector process, disrupting the endpoint's secure access to corporate resources via ZPA tunnels. In more severe scenarios, an attacker may achieve arbitrary code execution within the context of the ZCC process, which could allow access to sensitive data processed by the client, modification of ZCC behavior, or use of the compromised process as a foothold for further lateral movement on the endpoint. The confidentiality, integrity, and availability impacts are all rated High, reflecting the potential for full compromise of the ZCC process (Github Advisory).
As of the publication date, there is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Github Advisory). The NVD SSVC assessment confirms exploitation status as "none" and notes the vulnerability is not automatable, reflecting the high attack complexity required to reliably trigger the race condition. The EPSS score is 0.0, indicating a currently low probability of exploitation in the near term, and the CVE is not listed in the CISA Known Exploited Vulnerabilities catalog.
Zscaler has released patched versions of Client Connector addressing this vulnerability. Users should upgrade to version 4.6.0.486 or later (for the 4.6 branch), 4.7.0.350 or later (4.7 branch), 4.8.0.267 or later (4.8 branch), or 4.9.0.412 or later (4.9 branch) (Github Advisory). As a temporary measure where immediate patching is not feasible, organizations should consider implementing network controls to restrict ZPA tunnel connections from untrusted or unexpected sources, and monitor Zscaler's official release notes for further guidance (Zscaler Release Notes).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."