BoletimSec•August 26, 2026•🇵🇹Translated from Portuguese

Zscaler Fixes Multiple Critical Flaws in Client Connector Enabling RCE and Authentication Bypass

Zscaler has addressed multiple vulnerabilities in its Client Connector that could allow remote code execution, authentication bypass, privilege escalation, and denial of service.

The most critical issue, identified as CVE-2026-59568 and rated CVSS 9.1, combines several weaknesses that can be exploited remotely by an unauthenticated attacker without prior privileges. Successful exploitation grants the ability to run arbitrary code inside the Zscaler Client Connector process, potentially enabling malware installation, configuration changes, data theft, or further compromise of the affected device.

Another high-severity flaw, CVE-2026-59564, also scored CVSS 9.1, impacts the communication channel between the Client Connector and its management portal. This vulnerability permits attackers to bypass authentication controls and gain unauthorized access to management functions.

The advisory further covers local privilege escalation issues and conditions that may trigger denial of service. On Android and ChromeOS, CVE-2026-59566 (CVSS 8.4) involves a locally exploitable buffer overflow.

Affected platforms include Windows, macOS, Linux, iOS, Android, and ChromeOS, although the precise vulnerable builds differ by operating system. Zscaler has published corrected versions covering the 4.6, 4.7, 4.8, and 4.9 release lines on Windows along with corresponding updates for the remaining platforms.

Related articles

Hispasec•Vulnerabilities & Exploits

Critical CVE-2026-61500 in Rejetto HFS Allows Admin Session Forgery Leading to Remote Code Execution

A critical vulnerability tracked as CVE-2026-61500 is being actively exploited in Rejetto HTTP File Server (HFS), enabling unauthenticated attackers to forge administrator sessions and achieve remote code execution. The flaw impacts versions 3.0.0 through 3.2.0 and was addressed in release 3.2.1, making immediate updates essential for any internet-exposed instances. The root cause lies in the use of JavaScript Math.random() to generate the session cookie signing key instead of a cryptographically secure random number generator. Attackers can reconstruct the internal state of this weak PRNG from login responses, allowing them to create valid admin cookies. Once authenticated as an administrator, the attacker can abuse the server_code functionality to execute arbitrary JavaScript on the server. Exploitation activity was first observed on October 1, 2026, targeting U.S. systems and attributed to an unidentified actor based in China, following the public release of a Python proof-of-concept in late September.

BoletimSec•Vulnerabilities & Exploits

Dell Patches Six Critical Flaws in Container Storage Modules for Kubernetes

Dell has fixed six vulnerabilities in its Container Storage Modules that integrate storage systems with Kubernetes clusters. Two of the issues received the maximum CVSS score of 10.0, allowing remote unauthenticated attackers to obtain full administrative credentials for registered storage backends. Additional flaws enable privilege escalation to root on cluster nodes, exposure of hardcoded credentials, and leakage of Kubernetes secrets across the entire cluster. All versions prior to 1.17.0 are affected, with the fixes delivered in version 1.18.0. No workarounds exist, and Dell recommends rotating JWT signing keys after applying the update because the previous keys must be considered compromised.

Security NEXT•Vulnerabilities & Exploits

Critical Sandbox Bypass Flaw in GitLab AI Gateway Enables Remote Command Execution

GitLab has released patches for a critical vulnerability in its GitLab AI Gateway component that allows authenticated users to bypass sandbox restrictions and execute arbitrary commands. The flaw, tracked as CVE-2026-90970, resides in the custom flow prompt template processing of the Duo Agent Platform and carries a CVSS v3.1 base score of 9.9. Self-hosted deployments are affected, while GitLab’s own hosted AI Gateway service has already been updated. The company urges immediate upgrades to versions 19.4.1, 19.3.2, or 19.2.4. The vulnerability can be triggered under specific conditions by users with access to the Duo Agent Platform through crafted flow configurations.

Security NEXT•Vulnerabilities & Exploits

WebPros Releases Critical Patches for Three Vulnerabilities in cPanel & WHM

WebPros International has published security updates addressing three critical vulnerabilities in its cPanel & WHM hosting management platform. All three issues received the highest severity rating of Critical. The flaws include CVE-2026-93698, an input validation weakness in the Multilang adminbin component that could allow root-level operating system command execution. Two additional stored cross-site scripting vulnerabilities were also fixed, one of which is CVE-2026-93697 affecting the Mass Modify Accounts interface in WHM. Successful exploitation of the XSS flaws could let low-privileged accounts hijack administrator sessions. The updates were made available on September 29, 2026, and carry CVSS v3.0 base scores reaching 9.9.