Zscaler Fixes Multiple Critical Flaws in Client Connector Enabling RCE and Authentication Bypass
Zscaler has addressed multiple vulnerabilities in its Client Connector that could allow remote code execution, authentication bypass, privilege escalation, and denial of service.
The most critical issue, identified as CVE-2026-59568 and rated CVSS 9.1, combines several weaknesses that can be exploited remotely by an unauthenticated attacker without prior privileges. Successful exploitation grants the ability to run arbitrary code inside the Zscaler Client Connector process, potentially enabling malware installation, configuration changes, data theft, or further compromise of the affected device.
Another high-severity flaw, CVE-2026-59564, also scored CVSS 9.1, impacts the communication channel between the Client Connector and its management portal. This vulnerability permits attackers to bypass authentication controls and gain unauthorized access to management functions.
The advisory further covers local privilege escalation issues and conditions that may trigger denial of service. On Android and ChromeOS, CVE-2026-59566 (CVSS 8.4) involves a locally exploitable buffer overflow.
Affected platforms include Windows, macOS, Linux, iOS, Android, and ChromeOS, although the precise vulnerable builds differ by operating system. Zscaler has published corrected versions covering the 4.6, 4.7, 4.8, and 4.9 release lines on Windows along with corresponding updates for the remaining platforms.
Related articles
Out of 48,000 Vulnerabilities Only 1% Are Dangerous: How to Find Them Using CVSS 4.0, EPSS, KEV and FSTEC Methodology
The article explains why prioritizing vulnerabilities is critical in 2025-2026 as exploitation became the top initial access vector for the first time in 19 years according to Verizon DBIR. It details the limitations of CVSS scoring alone, the shift to CVSS 4.0 with new metrics like Attack Requirements and Supplemental Metrics, and the impact of NIST reducing NVD enrichment to only actively exploited or federal software cases. EPSS provides daily exploitation probability predictions using machine learning on over 1,100 features, while CISA KEV and the new LEV metric help identify confirmed or likely exploited vulnerabilities. The text covers practical prioritization criteria including asset significance, exploit availability, and network exposure, plus challenges for Russian infrastructure due to CVE dependency. It also compares CISA KEV with commercial catalogs like VulnCheck KEV that detect exploitation earlier.
Google Releases Chrome 152 Fixing 327 Vulnerabilities Including 10 Critical Flaws
Google has released Chrome 152 for Windows, macOS, and Linux, addressing a total of 327 security vulnerabilities. Ten of these issues received the highest severity rating of Critical. The update resolves multiple Use After Free flaws in core components such as ANGLE, Aura, and Chromecast. Specific CVEs fixed include CVE-2026-79282 in ANGLE and several others in Aura and Chromecast modules. The release targets memory corruption and input validation weaknesses that could lead to remote code execution. Users are strongly advised to apply the update immediately to mitigate potential exploitation risks.
Veeam ONE Receives Security Update Addressing Critical Vulnerabilities Including CVE-2026-65641
Veeam Software has released updates for its backup environment monitoring tool Veeam ONE to address multiple vulnerabilities. The advisory covers the 13.x series and includes fixes rated as critical under CVSSv4.0. One flaw, CVE-2026-65641, allows service accounts to perform SMB authentication and carries a base score of 9.3. Additional high-severity issues such as CVE-2026-64633 with a perfect 10.0 score were also resolved in the patches. The company updated its disclosure to include seven vulnerabilities fixed in version 13.1.0.7034 after initially reporting six. Patches are now available for both the 13.x and 12.x branches, with the latest 12.3 Patch 1 backporting several fixes from the 13 series.
Three Critical Vulnerabilities in Adobe Campaign Classic Allow Arbitrary Code Execution
Adobe has disclosed three severe vulnerabilities in Adobe Campaign Classic that could permit attackers to execute arbitrary code on affected systems. The issues affect both Windows and Linux versions and include two OS command injection flaws along with one server-side request forgery vulnerability. Each vulnerability received the maximum CVSSv3.1 base score of 10.0 and is rated Critical. Adobe released fixes in version 7.4.4 build 9401, which must be applied to on-premises components in both pure on-premises and hybrid environments. Although no active exploitation has been observed, Adobe assigned the highest priority level and recommends applying the update within 72 hours.