CVE-2026-59566
A locally exploitable buffer overflow bug can cause a local denial-of-service attack on affected versions of Zscaler Client Connector on And
CVSS
8.4
Alto
EPSS
0.1%
p2
KEV
—
Exploit Today
1
0-100
Publicado: 24 ago 2026 · Última mod.: 28 ago 2026 · CWE-229
0.1%EPSS · 30 días0.1%
2026-08-252026-08-31
A locally exploitable buffer overflow bug can cause a local denial-of-service attack on affected versions of Zscaler Client Connector on Android and ChromeOS.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-595658.8 ALT18.9%
——6A remotely exploitable buffer overflow bug can cause a local and kernel denial-of-service attack on affected versions of Zscaler Client Connector on Windows.3dCVE-2025-35973—1.0%
——0Improper handling of values for some Intel(R) Processors within Ring 0: Kernel, Hypervisor and Bare Metal OS may allow an escalation of privilege. Authorized adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and require no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (high) and availability (none) impacts.19dCVE-2026-456029.1 CRÍ29.5%
——9No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network.42dCVE-2025-590327.5 ALT50.8%
——15ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the service if it's not needed. Alternatively upgrade to a fixed version. No publicly available exploits are known.48dCVE-2024-204315.8 MED32.6%
——10A vulnerability in the geolocation access control feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass an access control policy.
This vulnerability is due to improper assignment of geolocation data. An attacker could exploit this vulnerability by sending traffic through an affected device. A successful exploit could allow the attacker to bypass a geolocation-based access control policy and successfully send traffic to a protected device.20d