CVE-2026-25687
A race condition in the ZPA tunnel handler of affected versions of Zscaler Client Connector (ZCC) allows a heap corruption, resulting in a denial of service (client crash) and potentially arbitrary code execution in the context of the ZCC process.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.1
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.23%
- CWE
- CWE-366
- Published
- 2026-09-14
- Last modified
- 2026-09-15
Affected products
- Zscaler Client Connector
- Zscaler Client Connector
- Zscaler Client Connector
- Zscaler Client Connector
Weakness type
Related vulnerabilities
- CVE-2021-26569 — Race Condition within a Thread vulnerability in iscsi_snapshot_comm_core in Synology DiskStation Manager (DSM) before 6.
- CVE-2024-10630 — A race condition in Ivanti Application Control Engine before version 10.14.4.0 allows a local authenticated attacker to
- CVE-2023-39198 — Kernel: qxl: race condition leading to use-after-free in qxl_mode_dumb_create()
- CVE-2025-31115 — XZ has a heap-use-after-free bug in threaded .xz decoder
- CVE-2023-4127 — Race Condition within a Thread in answerdev/answer
- CVE-2023-3218 — Race Condition within a Thread in it-novum/openitcockpit
- CVE-2020-1629 — Junos OS: A race condition vulnerability may cause RPD daemon to crash when processing a BGP NOTIFICATION message.
- CVE-2026-23684 — Race condition vulnerability in SAP Commerce Cloud