Vulnerabilities in Zscaler

43 results
Vexday analysis

Zscaler apresenta 43 vulnerabilidades catalogadas com apenas 2 críticas e nenhuma sob exploração ativa, indicando risco contido. A ausência de divulgações recentes e de ataques em andamento sugere que o portfólio foi estabilizado, embora a fraqueza dominante (CWE-347 - Improper Verification of Cryptographic Signature) permita monitoramento contínuo de possíveis desvios.

CVE-2021-26738HIGHPrivilege Escalation for ZCC macOS via PATH VariableEPSS 0.2%CVE-2023-28802MEDIUMDisable Zscaler using machine tunnel restartEPSS 0.2%CVE-2021-26736MEDIUMZApp Installer Privilege Escalation VulnerabilitiesEPSS 0.2%CVE-2023-28797MEDIUMLPE using arbitrary file delete with SymlinksEPSS 0.2%CVE-2024-23457HIGHAnti-tampering can be disabled with uninstall password enforcedEPSS 0.2%CVE-2023-28794MEDIUMPAC Files Exposed to Internet WebsitesEPSS 0.2%CVE-2026-22567HIGHZIA Admin UI Input Validation BugEPSS 0.2%CVE-2024-23462LOWZCC Mac validinstaller file integrity check missingEPSS 0.2%CVE-2023-28806MEDIUMSignature validation error in DLL allows disabling anti-tampering protectionEPSS 0.2%CVE-2023-41971MEDIUMWindows ZCC Upgrade DoS And Privilege Escalation Through RPC ControlEPSS 0.2%CVE-2023-28796HIGHIPC Bypass Through PLT Section in ELFEPSS 0.2%CVE-2026-22569MEDIUMIncorrect startup configuration in ZCCEPSS 0.2%CVE-2026-22568MEDIUMUnauthorized information retrieval in ZIA Admin UIEPSS 0.2%CVE-2023-28795HIGHClient IPC validation bypassEPSS 0.1%CVE-2021-26734MEDIUMJunction Delete leading to elevation of privilegeEPSS 0.1%CVE-2021-26735MEDIUMUntrusted Search Path While Executing REG DELETE by UninstallerEPSS 0.1%CVE-2024-23460MEDIUMIncorrect signature validation of packageEPSS 0.1%CVE-2025-54983MEDIUMHealth check port on ZCC allows tunnel bypassEPSS 0.1%CVE-2024-23458HIGHLocal Privilege Escalation on Zscaler Client Connector on WindowsEPSS 0.1%CVE-2024-23461MEDIUMZCC macOS Upgrade ZIP Bomb DoSEPSS 0.1%