DEV Community

Cover image for Zscaler Patches Critical Unauthenticated RCE in Client Connector for Windows
BeyondMachines for BeyondMachines

Posted on Originally published at beyondmachines.net

Zscaler Patches Critical Unauthenticated RCE in Client Connector for Windows

Summary

Zscaler fixed a critical vulnerability (CVE-2026-59568) that allowed unauthenticated remote code execution and privilege escalation as well as three other flaws in its Client Connector for Windows

Take Action:

If you use Zscaler Client Connector on Windows, update every endpoint to the latest patched version. Anything released before June 2026 (including 4.7.0.364, 4.8.0.232/284/291, and 4.9.0.448/455) is at risk of remote takeover. Don't assume your automated update policy reached every machine; manually verify the version on all devices. Check endpoint logs for odd processes launched by Zscaler components or unexpected new listening services.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)