CVE-2026-25684
File Type Control rule bypass
CVSS Score
4.4
EPSS Score
0.0%
EPSS Percentile
0th
A file type attribution issue in Zscaler Internet Access File Type Control evaluation rules may allow improper evaluation of File Type Control policies in rare circumstances.
| CWE | CWE-20 |
| Vendor | zscaler |
| Product | zia file type control |
| Published | Sep 18, 2026 |
Stay Ahead of the Next One
Get instant alerts for zscaler zia file type control
Be the first to know when new medium vulnerabilities affecting zscaler zia file type control are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Affected Versions
Zscaler / ZIA File Type Control
All versions affected References
Credits
Nate Subra and Nathan Fowler