Zscaler vulnerabilities
1 CVE tracked
Zscaler appears in our reporting primarily as an intelligence source, with its ThreatLabz team uncovering several advanced targeted campaigns. Key themes include multi-stage attacks against government entities in the Middle East, the targeting of Central and Eastern European countries in 'Operation Neusploit', and the rise of novel techniques like AI-generated 'ClickFix' campaigns. The only specific vulnerability highlighted is CVE-2026-21509, which is being exploited via specially crafted Microsoft RTF files. Defenders should pay close attention to this associated file type and heighten vigilance against diverse initial access vectors like AI-powered phishing and supply chain attacks.
Azərbaycanca: Zscaler hesabatlarımızda əsasən kəşfiyyat mənbəyi kimi çıxış edir, onların ThreatLabz bölməsi müxtəlif qabaqcıl hədəfli kampaniyaları aşkar edib. Əsas mövzulara hökumət qurumlarına qarşı Yaxın Şərqdə həyata keçirilən müxtəlif mərhələli hücumlar, 'Operation Neusploit' çərçivəsində Mərkəzi və Şərqi Avropanın hədəf alınması, həmçinin süni intellektdən istifadə edərək yaradılan 'ClickFix' kimi yeni texnikaların yayılması daxildir. Hesabatda xüsusilə qeyd olunan yeganə zəiflik spesifik Microsoft RTF faylları vasitəsilə istismar edilən CVE-2026-21509-dur. Müdafiəçilər bu əlaqəli fayl növünə qarşı diqqətli olmalı və süni intellektlə gücləndirilmiş fişinq, təchizat zənciri hücumları kimi müxtəlif ilkin giriş vektorlarına qarşı sayıqlığı artırmalıdır.
This vendor's CVEs1
This hub is built from skopnix's own reporting on Zscaler: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.