CVE-2026-59564CWE-304

CVE-2026-59564

Critical · published August 24, 2026

CVSS v3.1
9.1
EPSS
0%
Percentile
22.2
In the wild
Unconfirmed
What it is

An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and the Zscaler Client Connector Portal.

The record
Technical detail
CVSS v3.1
9.1 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00299 · 22.2th percentile
Weakness
CWE-304 · Missing Critical Step in Authentication
Published
2026-08-24T18:16Z
References (1)
EPSS history
Timeline
  • 26 AUG 08:16Z
    EPSS moved — → 0%
    epss
  • 24 AUG 13:39Z
    Authentication bypass between ZCC and client connector portal
    cvelistv5