CVE-2026-59564 CRITICAL

CVE-2026-59564: Authentication bypass between ZCC and client connector portal

Vendor Zscaler
Product Client Connector
Weakness CWE-304
Published August 24, 2026
Last update August 24, 2026

CVSS base score

9.1/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

What the vulnerability does

01Description

An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and the Zscaler Client Connector Portal.

Key dates

02Disclosure timeline

August 24, 2026 CVE published