CVE-2026-59566
Received Received - Intake

Buffer Overflow in Zscaler Client Connector

Vulnerability report for CVE-2026-59566, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-24

Last updated on: 2026-08-24

Assigner: Zscaler, Inc.

Description

A locally exploitable buffer overflow bug can cause a local denial-of-service attack on affected versions of Zscaler Client Connector on Android and ChromeOS.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-24
Last Modified
2026-08-24
Generated
2026-08-24
AI Q&A
2026-08-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zscaler zscaler_client_connector *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-229 The product does not properly handle when the expected number of values for parameters, fields, or arguments is not provided in input, or if those values are undefined.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a locally exploitable buffer overflow vulnerability in Zscaler Client Connector on Android and ChromeOS. It allows an attacker with local access to cause a denial-of-service condition by triggering a buffer overflow.

Detection Guidance

This vulnerability is a locally exploitable buffer overflow affecting Zscaler Client Connector on Android and ChromeOS. Detection requires checking installed versions of the software and monitoring for crashes or unusual behavior. No specific commands are provided in the available context.

Impact Analysis

An attacker with local access to your device could exploit this to crash the application or potentially execute arbitrary code, leading to system instability or unauthorized access.

Compliance Impact

The vulnerability is a locally exploitable buffer overflow causing denial-of-service on Android and ChromeOS. It does not explicitly mention data exposure or privacy impacts, so direct effects on GDPR or HIPAA compliance are unclear without further context.

Mitigation Strategies

Update Zscaler Client Connector to the latest version to patch the buffer overflow vulnerability. Disable the application if an update is not immediately available and monitor for unusual activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-59566. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart