Vulnerabilidades em Zscaler
52 resultadosAnálise Vexday
Zscaler apresenta 43 vulnerabilidades catalogadas com apenas 2 críticas e nenhuma sob exploração ativa, indicando risco contido. A ausência de divulgações recentes e de ataques em andamento sugere que o portfólio foi estabilizado, embora a fraqueza dominante (CWE-347 - Improper Verification of Cryptographic Signature) permita monitoramento contínuo de possíveis desvios.
CVE-2024-23483HIGHLocal Privilege Escalation via lack of input validationEPSS 0.7%CVE-2026-59568CRITICALRemote Code ExecutionEPSS 0.7%CVE-2023-28800HIGHOutput encoding missing in redrurl parameterEPSS 0.5%CVE-2026-59564CRITICALAuthentication bypass between ZCC and client connector portalEPSS 0.5%CVE-2026-59565HIGHLocal and kernel denial-of-serviceEPSS 0.5%CVE-2024-23459HIGHMultiple Arbitrary Creates/Overwrites by link followingEPSS 0.5%CVE-2023-28799HIGHA URL parameter during login flow was vulnerable to injection. An attacker could insert a malicious domain in this parameter, which would reEPSS 0.4%CVE-2023-28798MEDIUMOut-of-bounds write to heap in pacparserEPSS 0.4%CVE-2024-23464HIGHZscaler bypass with administrative privileges on WindowsEPSS 0.4%CVE-2025-54982CRITICALSAML 2.0 Public Key Validation IssueEPSS 0.4%CVE-2023-28801CRITICALImproper SAML signature verificationEPSS 0.4%CVE-2026-25687HIGHZCC race condition in ZPA tunnel handlerEPSS 0.4%CVE-2024-23463HIGHAnti-Tampering bypass via Repair App functionalityEPSS 0.4%CVE-2023-28805MEDIUMZCC on Linux privilege escalationEPSS 0.3%CVE-2023-28807MEDIUMBypass of ZIA domain fronting detection module through evasion techniqueEPSS 0.3%CVE-2023-41973HIGHLack of input santization on Zscaler Client Connector enables arbitrary code executionEPSS 0.3%CVE-2023-41969HIGHZSATrayManager Arbitrary File DeletionEPSS 0.3%CVE-2024-23480HIGHInsecure MacOS code sign check fallback EPSS 0.3%CVE-2023-28793HIGHHeap Based Buffer Overflow in LibraryEPSS 0.3%CVE-2024-23482HIGHZScalerService Local Privilege EscalationEPSS 0.3%