CVE-2026-59570
Received Received - Intake

Zscaler Tunnel Termination via Peer App

Vulnerability report for CVE-2026-59570, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: Zscaler, Inc.

Description

On affected versions of Zscaler client connector, a pre-installed peer app can tear down the Zscaler tunnel, force user logout, and toggle packet capture.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-15
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zscaler zscaler_client_connector *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows a pre-installed peer app on affected versions of Zscaler client connector to disrupt the Zscaler tunnel. It can force the user to log out, terminate the tunnel, and enable packet capture without authorization.

Detection Guidance

The vulnerability involves a pre-installed peer app disrupting the Zscaler tunnel. Monitor Zscaler client connector logs for unexpected tunnel disconnections or user logouts. Check for unauthorized packet capture toggles in system logs. Ensure no suspicious peer apps are installed alongside Zscaler client connector.

Impact Analysis

An attacker could exploit this to intercept network traffic, gain unauthorized access to sensitive data, or disrupt secure connections. Users may experience unexpected logouts and loss of VPN protection.

Compliance Impact

This vulnerability could lead to unauthorized data exposure or interception, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information. Compliance may be compromised due to loss of secure tunnel integrity.

Mitigation Strategies

Update Zscaler client connector to the latest patched version to prevent peer app interference. Disable unnecessary pre-installed peer apps that may interact with the tunnel. Monitor network logs for unusual tunnel disconnections or user logout events.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-59570. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart