Zscaler, Inc.
First CVE: Feb 16, 2021Active for: 5 years
47
CVEs Published
More CVEs Published than 56% of tracked CNAs
9.4
Avg CVEs / Year
More Avg CVEs / Year than 51% of tracked CNAs
7.3
Avg CVSS Score
Higher Avg CVSS Score than 58% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Zscaler, Inc. as a CNA, 95.7% affect products that Zscaler, Inc. develops as a vendor.
95.7%
Self-reported: 45Third-party: 2
Of all the CVEs published that affect products developed by Zscaler, Inc., 95.7% are self-published by Zscaler, Inc. as a CNA.
95.7%
Self-published: 45Published by other CNAs: 2
Trends Over Time
The number and severity of CVEs published by Zscaler, Inc. over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 16, 2021
5 years ago
Most Recent CVE
Mar 31, 2026
115 days ago
Top CVEs
All CVEs published by Zscaler, Inc. as a CNA, regardless of affected vendor or product.
47 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-54982CRITICAL An improper verification of cryptographic signature in Zscaler's SAML authentication mechanism on the server-side allowed an authentication abuse. | Aug 5, 2025 | 9.6 | 35 | NO | NO |
CVE-2020-11633CRITICAL The Zscaler Client Connector for Windows prior to 2.1.2.74 had a stack based buffer overflow when connecting to misconfigured TLS servers. An adversary would potentially have been | Jul 15, 2021 | 9.8 | 29 | NO | NO |
CVE-2024-23480CRITICAL A fallback mechanism in code sign checking on macOS may allow arbitrary code execution. This issue affects Zscaler Client Connector on MacOS prior to 4.2.
| May 1, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-23483CRITICAL An Improper Input Validation vulnerability in Zscaler Client Connector on MacOS allows OS Command Injection. This issue affects Zscaler Client Connector on MacOS <4.2. | Aug 6, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-23459CRITICAL An Improper Link Resolution Before File Access ('Link Following') vulnerability in Zscaler Client Connector on Mac allows a system file to be overwritten.This issue affects Zscaler | May 2, 2024 | 9.8 | 26 | NO | NO |
CVE-2023-28798CRITICAL An out-of-bounds write to heap in the pacparser library on Zscaler Client Connector on Mac may lead to arbitrary code execution. | May 2, 2024 | 9.8 | 26 | NO | NO |
CVE-2023-28805CRITICAL An Improper Input Validation vulnerability in Zscaler Client Connector on Linux allows Privilege Escalation. This issue affects Client Connector: before 1.4.0.105 | Oct 23, 2023 | 9.8 | 26 | NO | NO |
CVE-2023-41973HIGH ZSATray passes the previousInstallerName as a config parameter to TrayManager, and TrayManager constructs the path and appends previousInstallerName to get the full path of the exe | Mar 26, 2024 | 7.8 | 25 | NO | NO |
CVE-2023-41972HIGH In some rare cases, there is a password type validation missing in Revert Password check and for some features it could be disabled. Fixed Version: Win ZApp 4.3.0.121 and later. | Mar 26, 2024 | 7.8 | 24 | NO | NO |
CVE-2023-28801CRITICAL An Improper Verification of Cryptographic Signature in the SAML authentication of the Zscaler Admin UI allows a Privilege Escalation.This issue affects Admin UI: from 6.2 before 6. | Aug 31, 2023 | 9.8 | 24 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA47 CVEs
28%
51%
17%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local24 (51.1%)
Network22 (46.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (2.1%)
Attack Complexity
Low45 (95.7%)
High2 (4.3%)
Unknown0 (0.0%)
User Interaction
None40 (85.1%)
Unknown0 (0.0%)
Required7 (14.9%)
Privileges Required
Low24 (51.1%)
High3 (6.4%)
None20 (42.6%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (47 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Zscaler, Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Zscaler, Inc. as a CNA — matched by CVE ID, not by organization name.