CVE-2026-25687
Received Received - Intake

Heap Corruption in Zscaler Client Connector

Vulnerability report for CVE-2026-25687, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-15

Assigner: Zscaler, Inc.

Description

A race condition in the ZPA tunnel handler of affected versions of Zscaler Client Connector (ZCC) allows a heap corruption, resulting in a denial of service (client crash) and potentially arbitrary code execution in the context of the ZCC process.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-15
Generated
2026-09-15
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zscaler zscaler_client_connector *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-366 If two threads of execution use a resource simultaneously, there exists the possibility that resources may be used while invalid, in turn making the state of execution undefined.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a race condition in the ZPA tunnel handler of Zscaler Client Connector (ZCC). It can cause heap corruption, leading to a denial of service by crashing the client or potentially allowing arbitrary code execution within the ZCC process.

Detection Guidance

This vulnerability involves a race condition in the ZPA tunnel handler of Zscaler Client Connector (ZCC). Detection may require monitoring for client crashes or unusual heap corruption patterns in ZCC logs. Check for ZCC process crashes or logs indicating heap corruption. Review Zscaler Client Connector documentation for version-specific detection methods.

Impact Analysis

The impact includes system crashes due to denial of service, and in severe cases, attackers could execute malicious code on your device through the ZCC process, compromising its integrity and confidentiality.

Compliance Impact

This vulnerability could lead to unauthorized code execution, potentially exposing sensitive data. This may violate GDPR's data protection requirements and HIPAA's security rules, risking non-compliance and legal consequences.

Mitigation Strategies

Update Zscaler Client Connector to the latest version as soon as possible to address the race condition in the ZPA tunnel handler. Monitor ZCC process logs for crashes or unusual activity indicating exploitation attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-25687. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart