Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-25687
Zscaler Client Connector vulnerability analysis and mitigation

Overview

CVE-2026-25687 is a race condition vulnerability in the ZPA tunnel handler of Zscaler Client Connector (ZCC) that can lead to heap corruption, resulting in denial of service (client crash) and potentially arbitrary code execution within the ZCC process context. It was published on September 14, 2026, and assigned a CVSS v3.1 base score of 8.1 (High) (Github Advisory). Affected versions span the 4.6, 4.7, 4.8, and 4.9 release branches of Zscaler Client Connector, specifically versions prior to 4.6.0.486, 4.7.0.350, 4.8.0.267, and 4.9.0.412 respectively (Github Advisory).

Technical details

The vulnerability is classified as CWE-366 (Race Condition within a Thread), where two concurrent threads of execution access a shared resource simultaneously, leading to an undefined execution state and heap corruption in the ZPA tunnel handler component. An unauthenticated remote attacker can exploit this race condition over the network without requiring user interaction, though the high attack complexity (AC:H) indicates that exploitation requires precise timing or specific conditions to win the race (Github Advisory). The attack maps to CAPEC-26 (Leveraging Race Conditions) and CAPEC-29 (Leveraging Time-of-Check and Time-of-Use Race Conditions), suggesting the attacker must carefully time malicious requests to the ZPA tunnel handler to corrupt heap memory (Github Advisory).

Impact

Successful exploitation can result in a denial of service through a crash of the Zscaler Client Connector process, disrupting the endpoint's secure access to corporate resources via ZPA tunnels. In more severe scenarios, an attacker may achieve arbitrary code execution within the context of the ZCC process, which could allow access to sensitive data processed by the client, modification of ZCC behavior, or use of the compromised process as a foothold for further lateral movement on the endpoint. The confidentiality, integrity, and availability impacts are all rated High, reflecting the potential for full compromise of the ZCC process (Github Advisory).

Exploitability

As of the publication date, there is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Github Advisory). The NVD SSVC assessment confirms exploitation status as "none" and notes the vulnerability is not automatable, reflecting the high attack complexity required to reliably trigger the race condition. The EPSS score is 0.0, indicating a currently low probability of exploitation in the near term, and the CVE is not listed in the CISA Known Exploited Vulnerabilities catalog.

Mitigation and workarounds

Zscaler has released patched versions of Client Connector addressing this vulnerability. Users should upgrade to version 4.6.0.486 or later (for the 4.6 branch), 4.7.0.350 or later (4.7 branch), 4.8.0.267 or later (4.8 branch), or 4.9.0.412 or later (4.9 branch) (Github Advisory). As a temporary measure where immediate patching is not feasible, organizations should consider implementing network controls to restrict ZPA tunnel connections from untrusted or unexpected sources, and monitor Zscaler's official release notes for further guidance (Zscaler Release Notes).

Additional resources


SourceThis report was generated using AI

Related Zscaler Client Connector vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-23483CRITICAL9.8
  • Zscaler Client Connector logoZscaler Client Connector
  • cpe:2.3:a:zscaler:client_connector
NoYesAug 06, 2024
CVE-2026-25687HIGH8.1
  • Zscaler Client Connector logoZscaler Client Connector
  • cpe:2.3:a:zscaler:client_connector
NoYesSep 14, 2026
CVE-2024-31127HIGH7.3
  • Zscaler Client Connector logoZscaler Client Connector
  • cpe:2.3:a:zscaler:client_connector
NoYesJun 04, 2025
CVE-2026-22569MEDIUM5.3
  • Zscaler Client Connector logoZscaler Client Connector
  • cpe:2.3:a:zscaler:client_connector
NoYesMar 31, 2026
CVE-2024-23464MEDIUM4.9
  • Zscaler Client Connector logoZscaler Client Connector
  • cpe:2.3:a:zscaler:client_connector
NoYesAug 06, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management