Vulnerabilities & PatchesEmerging1 src
Critical Zscaler Client Connector Vulnerability Allows Remote Code Execution Without Login
A critical vulnerability in its Client Connector endpoint application that could allow an unauthenticated attacker to execute arbitrary code without requiring user interaction or valid login credentials.
Tracked as CVE-2026-59568, the flaw has received a CVSS v3. 1 score of 9. 1 and is classified as Critical.
The vulnerability is remotely exploitable over a network and requires neither privileges nor user interaction, creating a potentially severe exposure for enterprises that use Zscaler Client Connector on managed Windows endpoints .
The vulnerability carries the CVSS vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N , indicating that exploitation requires low attack complexity and can be initiated through network access.