<rss version="2.0" xml:base="https://help.zscaler.com/rss-feed/zscaler-client-connector/client-connector-app-release-summary-2026/Windows" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>Client Connector App Release Summary (2026)</title>
        <link>https://help.zscaler.com/rss-feed/zscaler-client-connector/client-connector-app-release-summary-2026/Windows</link>
        <description>Zscaler Client Connector app release summary for updates deployed, per OS and version, in 2026.</description>
        <lastBuildDate>Thu, 01 Oct 2026 16:59:21 +0000</lastBuildDate>
        <language>en-us</language>
        <atom:link href="https://help.zscaler.com/rss-feed/zscaler-client-connector/client-connector-app-release-summary-2026/Windows" rel="self" type="application/rss+xml" />
                            <item>
                <title>Zscaler Client Connector 4.10.0.477 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=Windows&amp;applicable_version=4.10.0.477&amp;deployment_date=2026-09-30&amp;id=1546192</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;e616647c15aa9ccd9b3e84df9abb88776&quot;&gt;Fixes an issue where default Wi-Fi interface binding issues could occur after upgrading Zscaler Client Connector, resulting in an Endpoint FW/AV error.&lt;/li&gt;&lt;li data-list-item-id=&quot;ef1970d8cdd50893489fa8957911d1b2e&quot;&gt;Fixes an issue where Zscaler Client Connector the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/viewing-information-about-private-access-zscaler-client-connector&quot; target=&quot;_blank&quot;&gt;VPN Service Edge&lt;/a&gt; as connected even after a network disconnect.&lt;/li&gt;&lt;li data-list-item-id=&quot;e4a1f1da98c7296f7b140979179a80f86&quot;&gt;Fixes an issue where users could not load their captive portal due to Zscaler Client Connector failing to detect the portal.&lt;/li&gt;&lt;li data-list-item-id=&quot;e1404f132f71839c9e49c3f12ba36d34a&quot;&gt;Updates VPN (for Legacy Apps) to continue retrying gateway connections with an exponential backoff capped at 60 seconds, even after 5 successive failures.&lt;/li&gt;&lt;li data-list-item-id=&quot;e760ab593208032b4cc595f9f53764ced&quot;&gt;Fixes an issue where, after reauthentication to Private Access, the Zscaler Client Connector app icon could disappear until a service restart.&lt;/li&gt;&lt;li data-list-item-id=&quot;e6b68a66ef463bdff7c286ad190faab5a&quot;&gt;Fixes an issue where the app could crash after a Private Access connection reset while Zscaler Client Connector was clearing buffered data after the connection closed.&lt;/li&gt;&lt;li data-list-item-id=&quot;e1c6c85a2e4296c48e977acf6a32d55a3&quot;&gt;Fixes an issue where, after removing and then re-adding a network segment, the routing table wasn&#039;t updated, preventing the user from connecting to that segment until they restarted Zscaler Client Connector.&lt;/li&gt;&lt;li data-list-item-id=&quot;ef3848c29bcbeab7813f41e3b261a2039&quot;&gt;Fixes an issue where Zscaler Client Connector correctly used the PAC file entered for &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/allowing-users-override-z-tunnel-2-0-or-private-access-protocol-settings&quot; target=&quot;_blank&quot;&gt;overriding protocol settings&lt;/a&gt; initially but then replaced it with the PAC file from the app profile.&lt;/li&gt;&lt;li data-list-item-id=&quot;ec283accbea00dc7ac80937cc9942d06e&quot;&gt;Fixes an issue where the app displayed the partner tenant username as the signed-in user when a user added or logged in to a partner tenant after enrolling in the main tenant.&lt;/li&gt;&lt;li data-list-item-id=&quot;ea76af6db25b6b5719888bc46569ba7d2&quot;&gt;Fixes a connectivity issue in Zscaler Tunnel (Z-Tunnel) 2.0 where enabling &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-forwarding-profiles-zscaler-client-connector#advanced-z-tunnel-config&quot; target=&quot;_blank&quot;&gt;Path MTU Discovery&lt;/a&gt; with DTLS failed to probe the path MTU correctly, causing packets to be silently dropped on lower-MTU paths.&lt;/li&gt;&lt;li data-list-item-id=&quot;e88341407f371b8eaae69a1e64cb40c57&quot;&gt;Fixes an issue where the Zscaler Client Connector tray icon could be missing and traffic could go directly to the web after a device resumed from sleep if the tunnel started before the tray process.&lt;/li&gt;&lt;li data-list-item-id=&quot;e0ea8064eb22be8d87de678234dbf64e8&quot;&gt;Fixes an issue in Zscaler Tunnel (Z-Tunnel) 2.0 where transient read failures during TLS renegotiation with Zscaler proxy servers could trigger unnecessary failover to the secondary tunnel and cause unexpected disconnections.&lt;/li&gt;&lt;li data-list-item-id=&quot;e6b72a783d6287e3597a6395fd56051d4&quot;&gt;Fixes an issue where single sign-on (SSO) failed and users were prompted to reauthenticate to Private Access when Zscaler Client Connector switched to Business Continuity mode while on a trusted network.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.10.0.477</version>
                                                <pubDate>Wed, 30 Sep 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1546192 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.9.0.481 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=Windows&amp;applicable_version=4.9.0.481&amp;deployment_date=2026-09-29&amp;id=1546161</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;eec83f61b301d67fc18f487d54b69fdce&quot;&gt;Fixes an issue where the app could crash after a Private Access connection reset while Zscaler Client Connector was clearing buffered data after the connection closed.&lt;/li&gt;&lt;li data-list-item-id=&quot;ec24f007ed5fb8be004013419f62c1fee&quot;&gt;Fixes an issue where Zscaler Client Connector correctly used the PAC file entered for &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/allowing-users-override-z-tunnel-2-0-or-private-access-protocol-settings&quot; target=&quot;_blank&quot; data-entity-type=&quot;node&quot; data-entity-uuid=&quot;dc7a4872-0bfc-43c9-a462-8068d25f6d33&quot; data-entity-substitution=&quot;canonical&quot;&gt;overriding protocol settings&lt;/a&gt; initially but then replaced it with the PAC file from the app profile.&lt;/li&gt;&lt;li data-list-item-id=&quot;e30255c4e3624ab48b68879140bdac823&quot;&gt;Fixes a connectivity issue in Zscaler Tunnel (Z-Tunnel) 2.0 where enabling &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-forwarding-profiles-zscaler-client-connector#advanced-z-tunnel-config&quot; target=&quot;_blank&quot;&gt;Path MTU Discovery&lt;/a&gt; with DTLS failed to probe the path MTU correctly, causing packets to be silently dropped on lower-MTU paths.&lt;/li&gt;&lt;li data-list-item-id=&quot;e87ad93a7922e81a7114972c3abd369e1&quot;&gt;Fixes an issue where the Zscaler Client Connector tray icon could be missing and traffic could go directly to the web after a device resumed from sleep if the tunnel started before the tray process.&lt;/li&gt;&lt;li data-list-item-id=&quot;edbfed16fc5e9d51ecbcc4c4afde281cc&quot;&gt;Fixes an issue where tray monitoring got stuck after a device entered sleep/hibernate mode, resulting in the app disappearing even though the Zscaler processes were still active.&lt;/li&gt;&lt;li data-list-item-id=&quot;e603aa8c43e532432a633856925a10e82&quot;&gt;Fixes an issue in Z-Tunnel 2.0 where transient read failures during TLS renegotiation with Zscaler proxy servers could trigger unnecessary failover to the secondary tunnel and cause unexpected disconnections.&lt;/li&gt;&lt;li data-list-item-id=&quot;ed070243a9cc548e7c8360adad99f5040&quot;&gt;Fixes an issue where single sign-on (SSO) failed and users were prompted to reauthenticate to Private Access when Zscaler Client Connector switched to Business Continuity mode while on a trusted network.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.9.0.481</version>
                                                <pubDate>Tue, 29 Sep 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1546161 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 5.0 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=Windows&amp;applicable_version=5.0&amp;deployment_date=2026-09-29&amp;id=1546134</link>
                <description>&lt;p class=&quot;note&quot;&gt;This version does not support Windows 32-bit. Zscaler recommends upgrading 32-bit to 64-bit. For help migrating to Windows 64-bit, refer to &lt;a class=&quot;url-external&quot; href=&quot;https://support.microsoft.com/en-us/windows/32-bit-and-64-bit-windows-frequently-asked-questions-c6ca9541-8dce-4d48-0415-94a3faa2e13d&quot; target=&quot;_blank&quot;&gt;the Microsoft documentation&lt;/a&gt;. To learn more, see the &lt;a class=&quot;url-external&quot; href=&quot;https://trust.zscaler.com/zscaler.net/posts/27196?_gl=1*bwmn1c*_gcl_au*MTYxNjU2OTE1Ni4xNzkwMDk3Mjgw*_ga*MTY3NzE0NzE2LjE2OTc1NTgwODM.*_ga_10SPJ4YJL9*czE3OTAzNTMxMjMkbzE4OTckZzEkdDE3OTAzNTMxMjUkajU4JGwwJGgxNzYxODI2NjA4&quot; target=&quot;_blank&quot;&gt;trust post&lt;/a&gt;.&lt;/p&gt;&lt;ul&gt;&lt;li data-list-item-id=&quot;e3ef16973531122f5ce1a7851dd8f885e&quot;&gt;Modernizes Zscaler Client Connector to provide users with clear status and actionable, natural-language guidance, while keeping technical details within easy reach if they need to engage Zscaler Support.&lt;/li&gt;&lt;li data-list-item-id=&quot;e90f973538a0a917cb1dda14e9baffa53&quot;&gt;Supports Wi-Fi Name (SSID) as a condition for trusted network criteria.&lt;/li&gt;&lt;li data-list-item-id=&quot;e9463423383b1a8573de7c70459258aeb&quot;&gt;Supports choosing either Packet Monitor (Pktmon) or Npcap as a diagnostic tool for local packet capture.&lt;/li&gt;&lt;li data-list-item-id=&quot;ea39b8cff2e713034b3eeee3c54691cc2&quot;&gt;Supports the TLS 1.3 protocol, and updates Zscaler Client Connector to automatically connect using TLS 1.3 and fall back to TLS 1.2 if the server doesn&#039;t support 1.3.&lt;/li&gt;&lt;li data-list-item-id=&quot;e06369c2c69b41c2795e2a7ae5c1f5326&quot;&gt;Supports an option in the app for the user to change the language in which the app displays to German.&lt;/li&gt;&lt;li data-list-item-id=&quot;e9cf27d9bfbcec498726caffceea03431&quot;&gt;Supports using machine tunnels in Business Continuity mode to allow devices to stay connected to Private Access apps when the Zscaler cloud is unreachable.&lt;/li&gt;&lt;li data-list-item-id=&quot;e44b7b7330a0c28b7c48492078261a118&quot;&gt;Supports using the WFP driver instead of Npcap when sending traceroute packets to Digital Experience.&lt;/li&gt;&lt;li data-list-item-id=&quot;ef46a7d99305c349863fb5d0f84e59811&quot;&gt;Supports entering Business Continuity during enrollment if a user experiences authentication failures or network issues. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-business-continuity-zscaler-client-connector&quot; target=&quot;_blank&quot;&gt;Configuring Business Continuity&lt;/a&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;e6a8294f10e1e3b1a796963a4a9e8eda0&quot;&gt;Enhances Business Continuity to enter Business Continuity mode during enrollment when Zscaler Client Connector can&#039;t reach the Zscaler Admin Console. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/about-business-continuity&quot; target=&quot;_blank&quot;&gt;About Business Continuity&lt;/a&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;ea0ea7de6cdfcca7d641d50bfd189c51d&quot;&gt;Improves the user-switching process for Imprivata integration, eliminating downtime during user switches, to help achieve better interoperability with applications such as Epic Systems. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/zscaler-client-connector-and-imprivata-integration&quot; target=&quot;_blank&quot;&gt;Zscaler Client Connector and Imprivata Integration&lt;/a&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;e9997cd7ff8d0f007811f3f49d695d6b5&quot;&gt;Supports using special formatting to add links and line breaks in end user notifications (EUNs) from Internet &amp; SaaS. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zia/about-zscaler-client-connector-based-end-user-notifications&quot; target=&quot;_blank&quot;&gt;About Zscaler Client Connector-Based End User Notifications&lt;/a&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;eb351073aa3c82ed2889ed5ae888f2a04&quot;&gt;Supports Endpoint Data Loss Prevention (DLP) on ARM processor-based Windows machines when using the ZDP Module version 26.08 and later. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zia/about-endpoint-dlp&quot; target=&quot;_blank&quot;&gt;About Endpoint Data Loss Prevention&lt;/a&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;e6eda6e30b641210619192a2ac3d462f6&quot;&gt;Supports using a Domain Public Key with the Business Continuity domain. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#Business_Continuity&quot; target=&quot;_blank&quot;&gt;Configuring Zscaler Client Connector App Profiles&lt;/a&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;e21d10938493c51a1ac814d9621dc6269&quot;&gt;Enhances Internet &amp; SaaS disaster recovery by supporting sending Zscaler Tunnel (Z-Tunnel) 2.0 traffic to the Business Continuity Cloud if Z-Tunnel 2.0 fails. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-forwarding-profiles-zscaler-client-connector&quot; target=&quot;_blank&quot;&gt;Configuring Forwarding Profiles for Zscaler Client Connector&lt;/a&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;ed9b36a0c585d1adbb3e092dda42ddbeb&quot;&gt;Supports using the ind.zscalertwo.net subcloud in the cloudName installation parameter for Zscaler Client Connector deployments in India.&lt;/li&gt;&lt;li data-list-item-id=&quot;eaa61fdc425d3dcfe1b8d16d0618f1bf6&quot;&gt;Enables automatic installation of the endpoint software used with Endpoint AI Security through Zscaler Client Connector. To learn more, contact your Zscaler Account team.&lt;/li&gt;&lt;li data-list-item-id=&quot;eaa28ed4c6529226cbeef8ca2557ae3e6&quot;&gt;Supports launching Zscaler Client Connector without waiting for the Windows desktop to display (which was prevented when another app such as Windows Autopilot occupied the full screen indefinitely) by adding an installation parameter to skip the requirement that the desktop be visible. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/supported-parameters-zscaler-client-connector-windows&quot; target=&quot;_blank&quot;&gt;Supported Parameters for Zscaler Client Connector for Windows&lt;/a&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;e16d127078c6a96c82f2b2f64eb0cde70&quot;&gt;Fixes an issue where Zscaler Client Connector disabled hardware offloading features in the LWF driver, even though Adapter Hardware Offloading was enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;ee30e21258cabdf453db8855001e8e576&quot;&gt;Fixes an issue where traffic bypassed for URLs with hostnames greater than 64 characters resulted in truncated hostnames in Internet &amp; SaaS logs when Flow Logging was enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;e9049e84249f05bb9a56a1b7e1dc3a43c&quot;&gt;Fixes an issue where users couldn&#039;t change their Windows password while Zscaler Client Connector was connected over a machine tunnel in Strict Enforcement mode.&lt;/li&gt;&lt;li data-list-item-id=&quot;e1c45dc45630de6e335fd28a56a575c70&quot;&gt;Fixes an issue where the private key could be exposed when using VPN (for Legacy Apps).&lt;/li&gt;&lt;li data-list-item-id=&quot;e39ea7504f4e4d55211da470286d42b58&quot;&gt;Fixes an issue where Zscaler Client Connector remained in a &lt;code&gt;Restarting service&lt;/code&gt; status after users clicked Restart Service in the app.&lt;/li&gt;&lt;li data-list-item-id=&quot;e5e94bdb36102e309ee5e2f75d72f4b2c&quot;&gt;Fixes an issue that caused intermittent DNS timeouts and sporadic connection instability for VPN traffic bypassed using process-based application bypasses.&lt;/li&gt;&lt;li data-list-item-id=&quot;e869581eed3993c3116f42893143c31f9&quot;&gt;Fixes an issue where Zscaler Client Connector failed to properly handle bursts of DNS requests, resulting in intermittent DNS failures and failures with Cisco ISE postures.&lt;/li&gt;&lt;li data-list-item-id=&quot;e51d8ac4e49c946f8bd9097281adbe683&quot;&gt;Fixes an issue where users received a &lt;code&gt;Chaining Authentication Error&lt;/code&gt; message if a manual policy update happened at the same time as a periodic policy update until they resolved the issue by updating the policy or restarting the Zscaler service.&lt;/li&gt;&lt;li data-list-item-id=&quot;e4993dd527bfac9235736396eba487c13&quot;&gt;Updates the Enable DTLS Instability Detection and Fallback option to improve response time when falling back to TLS after DTLS performance deteriorates.&lt;/li&gt;&lt;li data-list-item-id=&quot;efeca22e5a4cb85850854614c8663b473&quot;&gt;Fixes an issue with slow throughput that occurred when accessing an SMB (Server Message Block) file share through an app segment with the Double Encryption option enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;e6a915deed970da1bc8abfd977d876700&quot;&gt;Fixes an issue where, when using Dynamic ZIA Service Edge Assignment, Zscaler Client Connector didn’t display a user notification that the Service Edge had switched if the switch happened before the dynamic probes detected the issue.&lt;/li&gt;&lt;li data-list-item-id=&quot;e0fa15b592bba806c6451ed48de96624d&quot;&gt;Fixes an issue where the Disable ZIA OTP, Disable ZPA OTP, and Logout OTP one-time passwords failed for customers using Authentication Service due to a server and app password mismatch that occurred after registration.&lt;/li&gt;&lt;li data-list-item-id=&quot;ecd2c5913e0be5d327dc65257660aa10f&quot;&gt;Fixes an issue where, when the forwarding profile wasn&#039;t set to Enforce Proxy, Zscaler Client Connector removed the system proxy after exiting the app.&lt;/li&gt;&lt;li data-list-item-id=&quot;e8c0077b79d94e96f6b65ce5d25a458ea&quot;&gt;Fixes an issue where captive portal detection failed on networks using captive portals that return chunked HTTP responses (uncommon on guest Wi-Fi).&lt;/li&gt;&lt;li data-list-item-id=&quot;ef67659ddfb469d0cb55e6860633c7cd9&quot;&gt;Fixes an issue where Zscaler Client Connector remained in an On-Trusted Network after the device woke from standby or sleep mode, even if the network had changed.&lt;/li&gt;&lt;li data-list-item-id=&quot;e17387821c5e6b8b2950b7008de402725&quot;&gt;Upgrades the version of SQLite used by Zscaler Client Connector to SQLite version 3.53.1.&lt;/li&gt;&lt;li data-list-item-id=&quot;e21d8dd4b487f24b2c36428cf74c35368&quot;&gt;Fixes an issue where Private Access reauthentication was delayed or displayed a blank login page when using WebView2 authentication.&lt;/li&gt;&lt;li data-list-item-id=&quot;e5742ad5060db9056d0af13ce57ce1d92&quot;&gt;Fixes an issue where captive portal detection failed when a device connected to a captive portal that redirected Zscaler Client Connector to an HTTPS site on a non-standard port or to a site with an atypical URL path (e.g., no leading slash).&lt;/li&gt;&lt;li data-list-item-id=&quot;eb44474b60939a9c0db750cd919143f57&quot;&gt;Fixes an issue where users were prompted to reauthenticate Private Access even though Private Access was disabled on the network based on the network criteria.&lt;/li&gt;&lt;li data-list-item-id=&quot;efe0e0ddc6279ccc3c77f6349357bfdf1&quot;&gt;Fixes an issue where IP inclusions weren&#039;t enforced after a device resumed from a multi-day sleep, resulting in internet traffic bypassing Internet &amp; SaaS after switching network types.&lt;/li&gt;&lt;li data-list-item-id=&quot;e3d9ae2e9b50a34bb09acf90c3b72d7f0&quot;&gt;Fixes an issue where, even if the Restore LWF Adapter Binding feature was enabled, Zscaler Client Connector didn&#039;t attempt to rebind the adapter if the initial attempt failed.&lt;/li&gt;&lt;li data-list-item-id=&quot;eecc57712fa9919512781d2add7c9fc8d&quot;&gt;Updates the Enforce Secure PAC URLs feature to normalize HTTP URLs to HTTPS and to limit HTTP fallback.&lt;/li&gt;&lt;li data-list-item-id=&quot;e00c6345961b76e7dafe028f24a483a5b&quot;&gt;Fixes an issue where, if Zscaler Client Connector is upgraded, there could be a delay in installing the Zscaler Client Connector driver which could cause the system to enter an error state (display a blue screen) after the upgrade or system restart.&lt;/li&gt;&lt;li data-list-item-id=&quot;e68f54695ba9d29bd64c64eb3ea58821f&quot;&gt;Fixes an issue where Zscaler Client Connector continuously tried re-registering Private Access if the first attempt failed due to a SAML token request failure (e.g., an expired identity JWT) instead of retrying the token request.&lt;/li&gt;&lt;li data-list-item-id=&quot;e7fb9a14fc487ce0bbcc79d8a3d65bfdf&quot;&gt;Prevents memory corruption in the Private Access certificate timeout handler caused by race conditions. (CVE-2026-25687)&lt;/li&gt;&lt;li data-list-item-id=&quot;e0d730d5ba08f4ea1a6151d1645aa9974&quot;&gt;Fixes an issue where posture checks weren&#039;t evaluated correctly for a partner if the domain of the partner tenant is on a different cloud than the main tenant.&lt;/li&gt;&lt;li data-list-item-id=&quot;e9620a5724d185bd161eccd770adff72c&quot;&gt;Fixes an issue when using an SCCM virtual adapter where a tunnel crash could occur after traffic forwarding for Private Access switched and the Send Location Hint to Client Connector option was enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;e7d295c48be899f24db2c6b8dc37b2791&quot;&gt;Fixes an issue with the fail-close, application bypass, block domain profile detection, and captive portal lockdown features that could cause a tunnel crash.&lt;/li&gt;&lt;li data-list-item-id=&quot;e726cc569cfa1baf5f978b593523f97ed&quot;&gt;Fixes an issue where, in a no-default route environment, policy updates were sent directly instead of through the tunnel even though Tunnel Internal Client Connector Traffic was enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;e2bfca8d8e8261a6d54a16d04d7c1291d&quot;&gt;Fixes an issue where Acceptable Use Policy (AUP) data was reset during Private Access reauthentication, resulting in Private Access entitlement being removed for multiple users.&lt;/li&gt;&lt;li data-list-item-id=&quot;e4848ace8e964dbc1b43f1fbb4ae8d12b&quot;&gt;Fixes an issue where notifications from the Zscaler Notification Framework were brought into focus even though the Bring Notification to Focus option was disabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;e046ea252ea4b55fe3c6786c364bf6d5d&quot;&gt;Fixes an issue where the policy download for a partner tenant didn&#039;t include the Ignore Client Cert errors for Webview 2 value, leading to partner tenant reauthentication failures.&lt;/li&gt;&lt;li data-list-item-id=&quot;ed74d5aec773ec6be3350b881a65899a4&quot;&gt;Fixes an issue where, for devices authenticating with an IdP as a Private Access app segment and using the machine tunnel on a network identified by Trusted Network Criteria, first-time enrollment failed during Private Access registration if the app profile had Business Continuity enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;e08adf7a931c98d8e345fbb605eb70da1&quot;&gt;Fixes an issue where, if the forwarding PAC file for the Off-Trusted Network wasn&#039;t reachable, Zscaler Client Connector applied the forwarding PAC file for the On-Trusted Network after switching from a trusted to untrusted network.&lt;/li&gt;&lt;li data-list-item-id=&quot;e9955417ed38c9178dfcbaf3d55322c56&quot;&gt;Fixes an issue where the Update App and Update Policy options on the More window in the app disappeared after activating and deactivating Business Continuity mode.&lt;/li&gt;&lt;li data-list-item-id=&quot;e1179a1c792dfa4499cb6bac787a2fae8&quot;&gt;Fixes an issue where VPN Service Edge tunnel connections intermittently failed or dropped after logging off and then logging back in to Windows.&lt;/li&gt;&lt;li data-list-item-id=&quot;e651d74cc46dd97119a1a37611722d8b7&quot;&gt;Updates the network detection process to treat network detection failures as being on an Off-Trusted Network to prevent devices from remaining in an On-Trusted Network state if DNS hostname resolution is delayed.&lt;/li&gt;&lt;li data-list-item-id=&quot;e1c9a17bd2c6a046be5162104dfc1e4c3&quot;&gt;Fixes an issue where Zscaler Client Connector used weak cipher suites when performing the CRL check for the Client Certificate device posture check.&lt;/li&gt;&lt;li data-list-item-id=&quot;ebb2e473b4460c1fedfed88a746f9aa21&quot;&gt;Fixes an issue where fragmented packet handling in Zscaler Client Connector could cause the tunnel service to become unresponsive and temporarily disrupt network connectivity.&lt;/li&gt;&lt;li data-list-item-id=&quot;eba71695d264cb40d0d8b4474f55acd63&quot;&gt;Fixes an issue where users couldn’t access Private Access resources when the DNS responses, such as SRV (Service) records, were large and occasionally became fragmented.&lt;/li&gt;&lt;li data-list-item-id=&quot;e97d78064531f8eba233ead592f17c81e&quot;&gt;Fixes an issue where file uploads using WinSCP (Windows Secure Copy) became progressively slower when connecting to an FTP-SFTP server using Private Access.&lt;/li&gt;&lt;li data-list-item-id=&quot;ef9b659b1ce361475e5b0070a9cb010da&quot;&gt;Fixes a Windows registry value to prevent unquoted service path enumeration.&lt;/li&gt;&lt;li data-list-item-id=&quot;eb3b5e53aec54bf15e46dd5da9a7f11a3&quot;&gt;Updates the ZEP installer that installs anti-tampering protection to mitigate a security vulnerability that could allow code injections.&lt;/li&gt;&lt;li data-list-item-id=&quot;e3f6891c56bf4bd6caf26393f1dcc2041&quot;&gt;Fixes an issue where Zscaler Client Connector continued to populate the username field in the IdP login with the SAM account name after customers updated the Username Format to use the User Principal Name.&lt;/li&gt;&lt;li data-list-item-id=&quot;ece5b076cd84a6fc3067ca46bbb8e445b&quot;&gt;Fixes an issue where, if customers had many trusted networks with hostname-based trusted network criteria, Zscaler Client Connector remained in a &lt;code&gt;Connecting&lt;/code&gt; state due to resolving the same hostname individually for each trusted network.&lt;/li&gt;&lt;li data-list-item-id=&quot;e1a05d2e1e8fa79504f1d2293a4d559f4&quot;&gt;Fixes an issue where Zscaler Client Connector displayed the default notification after a transaction was blocked by a Data Loss Prevention (DLP) policy rule instead of the notification from the DLP template.&lt;/li&gt;&lt;li data-list-item-id=&quot;eb75889539e1d90662e494dc3d90b6a9c&quot;&gt;Fixes an issue where endpoint activity wasn&#039;t detected if Endpoint Data Loss Prevention (DLP) was enabled for a user before the user enrolled in Zscaler Client Connector.&lt;/li&gt;&lt;li data-list-item-id=&quot;ef39d98a37f61209fa73f52cbd637fb47&quot;&gt;Fixes an issue where the Firewall device posture check failed if any firewall profile had been disabled by a GPO policy even if another profile was enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;eaec368b768e0aa2b8469c7b6a6d96b2d&quot;&gt;Fixes high CPU usage due to an issue with captive portal detection that occurred when Zscaler Client Connector failed to resolve or connect through the local proxy.&lt;/li&gt;&lt;li data-list-item-id=&quot;e2d641d9e6fe6c8a0a9b9ddfdc04f1902&quot;&gt;Fixes an issue where Authentication Service users received an &lt;code&gt;Inconsistency in user credentials is detected&lt;/code&gt; error when reauthenticating to Private Access.&lt;/li&gt;&lt;li data-list-item-id=&quot;e3b69d8d320c393e42bc916ca0145d2b2&quot;&gt;Fixes an issue where Zscaler Client Connector could experience frequent disconnections on devices with another application that modifies OpenSSL environment variables when FIPS-compliant libraries are enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;e7452b2365d64fbb631bf822e92f1f0cf&quot;&gt;Fixes an issue where Zscaler Client Connector remained in a &lt;code&gt;Connecting&lt;/code&gt; state or the ZSATunnel process didn&#039;t start when running on AWS VDI environments using Windows Server 2019 or Windows Server 2022.&lt;/li&gt;&lt;li data-list-item-id=&quot;e2c0e10a949a70f42ecf7e0e6f56a173a&quot;&gt;Fixes an issue where default Wi-Fi interface binding issues could occur after upgrading Zscaler Client Connector, resulting in an Endpoint FW/AV error.&lt;/li&gt;&lt;li data-list-item-id=&quot;ed72305f10947b5b42b90d6476fa83bf5&quot;&gt;Fixes an issue where Zscaler Client Connector showed the VPN Service Edge as connected even after a network disconnect.&lt;/li&gt;&lt;li data-list-item-id=&quot;eac5dfeaf966b864225bfdaf5b36042b7&quot;&gt;Fixes an issue where users could not load their captive portal due to Zscaler Client Connector failing to detect the portal.&lt;/li&gt;&lt;li data-list-item-id=&quot;e8cd9c339397e027c0991f2f862346437&quot;&gt;Fixes an issue where, after reauthentication to Private Access, the Zscaler Client Connector app icon could disappear until a service restart.&lt;/li&gt;&lt;li data-list-item-id=&quot;ebe318e90bb1fefaea33e33db0f660344&quot;&gt;Fixes an issue where the app could crash after a Private Access connection reset while Zscaler Client Connector was clearing buffered data after the connection closed.&lt;/li&gt;&lt;li data-list-item-id=&quot;ec53fd1b4aaa1ee03dbb2fd9270487760&quot;&gt;Fixes an issue where, after removing and then re-adding a network segment, the routing table wasn&#039;t updated, preventing the user from connecting to that segment until they restarted Zscaler Client Connector.&lt;/li&gt;&lt;li data-list-item-id=&quot;e79dc264b97ae5c75414d79f971d2f195&quot;&gt;Fixes an issue where Zscaler Client Connector correctly used the PAC file entered for &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/allowing-users-override-z-tunnel-2-0-or-private-access-protocol-settings&quot; target=&quot;_blank&quot; data-entity-type=&quot;node&quot; data-entity-uuid=&quot;dc7a4872-0bfc-43c9-a462-8068d25f6d33&quot; data-entity-substitution=&quot;canonical&quot;&gt;overriding protocol settings&lt;/a&gt; initially but then replaced it with the PAC file from the app profile.&lt;/li&gt;&lt;li data-list-item-id=&quot;e19a79099378a84ba849bd79da3eda475&quot;&gt;Fixes an issue where the app displayed the partner tenant username as the signed-in user when a user added or logged in to a partner tenant after enrolling in the main tenant.&lt;/li&gt;&lt;li data-list-item-id=&quot;e59dd8b11d1d0b203080530a0bc71c675&quot;&gt;Fixes a connectivity issue in Z-Tunnel 2.0 where enabling &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-forwarding-profiles-zscaler-client-connector#advanced-z-tunnel-config&quot; target=&quot;_blank&quot;&gt;Path MTU Discovery&lt;/a&gt; with DTLS failed to probe the path MTU correctly, causing packets to be silently dropped on lower-MTU paths.&lt;/li&gt;&lt;li data-list-item-id=&quot;ea4e35e9eae84f0105295cb530e8d4a93&quot;&gt;Fixes an issue where the Zscaler Client Connector tray icon could be missing and traffic could go directly to the web after a device resumed from sleep if the tunnel started before the tray process.&lt;/li&gt;&lt;li data-list-item-id=&quot;ed6c7484ed63a06f8231edd41b997e3bb&quot;&gt;Fixes an issue where tray monitoring got stuck after a device entered sleep/hibernate mode, resulting in the app disappearing even though the Zscaler processes were still active.&lt;/li&gt;&lt;li data-list-item-id=&quot;ebb298c570cca803da3e03fab44d6855f&quot;&gt;Fixes an issue in Z-Tunnel 2.0 where transient read failures during TLS renegotiation with Zscaler proxy servers could trigger unnecessary failover to the secondary tunnel and cause unexpected disconnections.&lt;/li&gt;&lt;li data-list-item-id=&quot;e5208ddb67b47cedf2ca5f50b676cb325&quot;&gt;Fixes an issue where access to Microsoft 365 resources was blocked and a &lt;code&gt;W365 blocked: Non-compliant machine&lt;/code&gt; message displayed due to an incorrect Firewall device posture check failure.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release in Limited Availability</category>
                                    <version>5.0</version>
                                                <pubDate>Tue, 29 Sep 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1546134 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.7.0.382 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=Windows&amp;applicable_version=4.7.0.382&amp;deployment_date=2026-09-28&amp;id=1546160</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;e6158e944dc97275e79d813b6cb623176&quot;&gt;Fixes an issue where, if the Windows certificate store included an unsupported certificate, the app disappeared from the system tray and Zscaler Client Connector consumed excessive memory.&lt;/li&gt;&lt;li data-list-item-id=&quot;e15bf136a27dc8cd60a5e69d4e460bc9d&quot;&gt;Fixes an issue where, after reauthentication to Private Access, the Zscaler Client Connector app icon could disappear until a service restart.&lt;/li&gt;&lt;li data-list-item-id=&quot;ececebb7be8822af6bebebfeb1956e199&quot;&gt;Fixes an issue where the app displayed the partner tenant username as the signed-in user when a user added or logged in to a partner tenant after enrolling in the main tenant.&lt;/li&gt;&lt;li data-list-item-id=&quot;eccb365dcc9cffb68fa086cd230af06f9&quot;&gt;Fixes a connectivity issue in Zscaler Tunnel (Z-Tunnel) 2.0 where enabling &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-forwarding-profiles-zscaler-client-connector#advanced-z-tunnel-config&quot; target=&quot;_blank&quot;&gt;Path MTU Discovery&lt;/a&gt; with DTLS failed to probe the path MTU correctly, causing packets to be silently dropped on lower-MTU paths.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.7.0.382</version>
                                                <pubDate>Mon, 28 Sep 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1546160 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.8.0.312 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=Windows&amp;applicable_version=4.8.0.312&amp;deployment_date=2026-09-28&amp;id=1546146</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;ebc84d86942c6439ef591e402b670fd6d&quot;&gt;Fixes an issue where default Wi-Fi interface binding issues could occur after upgrading Zscaler Client Connector, resulting in an Endpoint FW/AV error.&lt;/li&gt;&lt;li data-list-item-id=&quot;e69372b5672b95f40134764dc6ffbc17e&quot;&gt;Fixes an issue where users could not load their captive portal due to Zscaler Client Connector failing to detect the portal.&lt;/li&gt;&lt;li data-list-item-id=&quot;e48a0b5e858d16b933f872f1d69b650f3&quot;&gt;Fixes an issue where, if the Windows certificate store included an unsupported certificate, the app disappeared from the system tray and Zscaler Client Connector consumed excessive memory.&lt;/li&gt;&lt;li data-list-item-id=&quot;e01e45a6d64d43818b0e5cb496f410124&quot;&gt;Fixes an issue where, after reauthentication to Private Access, the Zscaler Client Connector app icon could disappear until a service restart.&lt;/li&gt;&lt;li data-list-item-id=&quot;e3d35bef80ae074f112a89fac661dcc79&quot;&gt;Fixes an issue where the app could crash after a Private Access connection reset while Zscaler Client Connector was clearing buffered data after the connection closed.&lt;/li&gt;&lt;li data-list-item-id=&quot;e46770c9cf7148098dc0a12dc460bc3cf&quot;&gt;Fixes an issue where, after removing and then re-adding a network segment, the routing table wasn&#039;t updated, preventing the user from connecting to that segment until they restarted Zscaler Client Connector.&lt;/li&gt;&lt;li data-list-item-id=&quot;e67acf9cf9145e377d681d30e42f65d5b&quot;&gt;Fixes an issue where the app displayed the partner tenant username as the signed-in user when a user added or logged in to a partner tenant after enrolling in the main tenant.&lt;/li&gt;&lt;li data-list-item-id=&quot;edf9f7e3773cc113dd3d90e769987ffb9&quot;&gt;Fixes a connectivity issue in Z-Tunnel 2.0 where enabling &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-forwarding-profiles-zscaler-client-connector#advanced-z-tunnel-config&quot; target=&quot;_blank&quot;&gt;Path MTU Discovery&lt;/a&gt; with DTLS failed to probe the path MTU correctly, causing packets to be silently dropped on lower-MTU paths.&lt;/li&gt;&lt;li data-list-item-id=&quot;e6da826cdb6437f52f6b76bf82501d058&quot;&gt;Fixes an issue where tray monitoring got stuck after a device entered sleep/hibernate mode, resulting in the app disappearing even though the Zscaler processes were still active.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.8.0.312</version>
                                                <pubDate>Mon, 28 Sep 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1546146 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.10.0.463 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=Windows&amp;applicable_version=4.10.0.463&amp;deployment_date=2026-09-15&amp;id=1543257</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;ed4a1748fe3c5533b0651ddd537fb8c33&quot;&gt;Improves the user-switching process for Imprivata integration, eliminating downtime during user switches, to help achieve better interoperability with applications such as Epic Systems. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/zscaler-client-connector-and-imprivata-integration&quot; target=&quot;_blank&quot;&gt;Zscaler Client Connector and Imprivata Integration&lt;/a&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;e309ddeae9683af4312e4e6b9771ebbba&quot;&gt;Supports Endpoint Data Loss Prevention (DLP) on ARM processor-based Windows machines when using the ZDP Module version 26.08 and later. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zia/about-endpoint-dlp&quot; target=&quot;_blank&quot;&gt;About Endpoint Data Loss Prevention&lt;/a&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;e6ce0a4a5820f56292b0603cdfad62e56&quot;&gt;Supports launching Zscaler Client Connector without waiting for the Windows desktop to display (which was prevented when another app such as Windows Autopilot occupied the full screen indefinitely) by adding an installation parameter to skip the requirement that the desktop be visible. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/supported-parameters-zscaler-client-connector-windows&quot; target=&quot;_blank&quot;&gt;Supported Parameters for Zscaler Client Connector for Windows&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.10.0.463</version>
                                                <pubDate>Tue, 15 Sep 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1543257 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.7.0.376 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=Windows&amp;applicable_version=4.7.0.376&amp;deployment_date=2026-08-31&amp;id=1543154</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;ed345d26f285d14afa48685d0817d1500&quot;&gt;Fixes an issue where, in a no-default route environment with an explicit external proxy, users could receive an &lt;code&gt;Internet Unreachable&lt;/code&gt; or &lt;code&gt;Server Down&lt;/code&gt; error when accessing Zscaler Client Connector through a machine tunnel.&lt;/li&gt;&lt;li data-list-item-id=&quot;e2248316bae15673d14474ae9b912e60f&quot;&gt;Fixes an issue where the policy download for a partner tenant didn&#039;t include the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/using-webview2-authentication&quot; target=&quot;_blank&quot;&gt;Ignore Client Cert errors for Webview 2&lt;/a&gt; value, leading to partner tenant reauthentication failures.&lt;/li&gt;&lt;li data-list-item-id=&quot;e29833e61e41ddc2ddae5c6b987112bb3&quot;&gt;Fixes an issue where endpoint activity wasn&#039;t detected if &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/about-endpoint-dlp&quot; target=&quot;_blank&quot;&gt;Endpoint Data Loss Protection (DLP)&lt;/a&gt; was enabled for a user before the user enrolled in Zscaler Client Connector.&lt;/li&gt;&lt;li data-list-item-id=&quot;e85b26ce4eefd06105ff910b0781f4423&quot;&gt;Fixes an issue where Authentication Service users received an &lt;code&gt;Inconsistency in user credentials is detected&lt;/code&gt; error when reauthenticating to Private Access.&lt;/li&gt;&lt;li data-list-item-id=&quot;e43b900b6d412f25c666a93854c18a49b&quot;&gt;Fixes an issue where Zscaler Client Connector didn’t send the platform variable to Private Access for Authentication Service tenants, causing issues with policies based on the platform and with App Scaling.&lt;/li&gt;&lt;li data-list-item-id=&quot;e35012922fb73ea0953dd467306beaf79&quot;&gt;Fixes an issue where Zscaler Client Connector didn&#039;t connect to the &lt;a href=&quot;https://help.zscaler.com/zpa/about-vpn-service-edges&quot; target=&quot;_blank&quot;&gt;VPN Service Edge&lt;/a&gt; after the device woke from sleep until users clicked &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/troubleshooting-zscaler-client-connector#win&quot; target=&quot;_blank&quot;&gt;Restart Service&lt;/a&gt; in the app.&lt;/li&gt;&lt;li data-list-item-id=&quot;ee01ef8e287cd6b20927c7bd77c0d024b&quot;&gt;Fixes an issue where some applications could load slowly due to Zscaler Client Connector delays when rejecting invalid requests to the loopback proxy server.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.7.0.376</version>
                                                <pubDate>Mon, 31 Aug 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1543154 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.8.0.300 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=Windows&amp;applicable_version=4.8.0.300&amp;deployment_date=2026-08-31&amp;id=1543076</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;e5784b7376bfdfa11dbf7a90d802cec4c&quot;&gt;Fixes an issue where Zscaler Client Connector remained in a &lt;code&gt;Restarting service&lt;/code&gt; status after users clicked &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/troubleshooting-zscaler-client-connector#win&quot; target=&quot;_blank&quot;&gt;Restart Service&lt;/a&gt; in the app.&lt;/li&gt;&lt;li data-list-item-id=&quot;ec9bf0b0eaa222750b787b68a3503f69f&quot;&gt;Fixes an issue where, in a no-default route environment with an explicit external proxy, users could receive an &lt;code&gt;Internet Unreachable&lt;/code&gt; or &lt;code&gt;Server Down&lt;/code&gt; error when accessing Zscaler Client Connector through a machine tunnel.&lt;/li&gt;&lt;li data-list-item-id=&quot;e454b6049cb76f3f197f23a35ff2a1967&quot;&gt;Fixes an issue where the policy download for a partner tenant didn&#039;t include the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/using-webview2-authentication&quot; target=&quot;_blank&quot;&gt;Ignore Client Cert errors for Webview 2&lt;/a&gt; value, leading to partner tenant reauthentication failures.&lt;/li&gt;&lt;li data-list-item-id=&quot;ee65893b227aca9cbb7c9a7e6bac3cfd3&quot;&gt;Fixes an issue where endpoint activity wasn&#039;t detected if &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/about-endpoint-dlp&quot; target=&quot;_blank&quot;&gt;Endpoint Data Loss Protection (DLP)&lt;/a&gt; was enabled for a user before the user enrolled in Zscaler Client Connector.&lt;/li&gt;&lt;li data-list-item-id=&quot;e692e9ab975046b16d95dbf559c0c3952&quot;&gt;Fixes an issue where Authentication Service users received an &lt;code&gt;Inconsistency in user credentials is detected&lt;/code&gt; error when reauthenticating to Private Access.&lt;/li&gt;&lt;li data-list-item-id=&quot;e17e5103122230b1b69395f88c49e6547&quot;&gt;Fixes an issue where Zscaler Client Connector didn&#039;t connect to the &lt;a href=&quot;https://help.zscaler.com/zpa/about-vpn-service-edges&quot; target=&quot;_blank&quot;&gt;VPN Service Edge&lt;/a&gt; after the device woke from sleep until users clicked &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/troubleshooting-zscaler-client-connector#win&quot; target=&quot;_blank&quot;&gt;Restart Service&lt;/a&gt; in the app.&lt;/li&gt;&lt;li data-list-item-id=&quot;ebe30006178a78545b962eef8a05d44bd&quot;&gt;Fixes an issue where Zscaler Client Connector showed the &lt;a href=&quot;https://help.zscaler.com/zpa/about-vpn-service-edges&quot; target=&quot;_blank&quot;&gt;VPN Service Edge&lt;/a&gt; as connected even after a network disconnect.&lt;/li&gt;&lt;li data-list-item-id=&quot;e0eb9f072d0555313da3543c8fdac4d05&quot;&gt;Fixes an issue where Zscaler Client Connector didn&#039;t send updated host details after a customer migrated their virtual machines (VMs) to another VDI vendor, causing the Device Details section on the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/viewing-device-fingerprint-enrolled-device&quot; target=&quot;_blank&quot;&gt;Zscaler Client Connector Registered Device Details&lt;/a&gt; window to display outdated information.&lt;/li&gt;&lt;li data-list-item-id=&quot;e9a8a7b7713745dc0f3643d967c12b4d5&quot;&gt;Fixes an issue where some applications could load slowly due to Zscaler Client Connector delays when rejecting invalid requests to the loopback proxy server.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.8.0.300</version>
                                                <pubDate>Mon, 31 Aug 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1543076 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.9.0.465 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=Windows&amp;applicable_version=4.9.0.465&amp;deployment_date=2026-08-31&amp;id=1543071</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;e2b964aedfa593865fcc84910c2f7c67b&quot;&gt;Fixes an issue where Zscaler Client Connector remained in a &lt;code&gt;Restarting service&lt;/code&gt; status after users clicked &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/troubleshooting-zscaler-client-connector#win&quot; target=&quot;_blank&quot;&gt;Restart Service&lt;/a&gt; in the app.&lt;/li&gt;&lt;li data-list-item-id=&quot;ecfa588680a254f62de6582ec34751f1f&quot;&gt;Fixes an issue where, in a no-default route environment with an explicit external proxy, users could receive an &lt;code&gt;Internet Unreachable&lt;/code&gt; or &lt;code&gt;Server Down&lt;/code&gt; error when accessing Zscaler Client Connector through a machine tunnel.&lt;/li&gt;&lt;li data-list-item-id=&quot;ea5c9ad08a4cdb9c023dac6e048a18423&quot;&gt;Fixes an issue where the policy download for a partner tenant didn&#039;t include the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/using-webview2-authentication&quot; target=&quot;_blank&quot;&gt;Ignore Client Cert errors for Webview 2&lt;/a&gt; value, leading to partner tenant reauthentication failures.&lt;/li&gt;&lt;li data-list-item-id=&quot;e5931992beb844ea2ff9f35f44eda1230&quot;&gt;Fixes an issue where Zscaler Client Connector continued to populate the username field in the IdP login with the SAM account name after customers updated the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-automatic-username-population-idp-authentication&quot; target=&quot;_blank&quot;&gt;Username Format&lt;/a&gt; to use the User Principal Name.&lt;/li&gt;&lt;li data-list-item-id=&quot;edab2dd735248b57cdb51019f0303fcca&quot;&gt;Fixes an issue where, if customers had many trusted networks with hostname-based &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-trusted-networks-zscaler-client-connector&quot; target=&quot;_blank&quot;&gt;trusted network criteria&lt;/a&gt;, Zscaler Client Connector remained in a &lt;code&gt;Connecting&lt;/code&gt; state due to resolving the same hostname individually for each trusted network.&lt;/li&gt;&lt;li data-list-item-id=&quot;e9a10b15aebf53bd410f3e3e800dfee6b&quot;&gt;Fixes an issue where endpoint activity wasn&#039;t detected if &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/about-endpoint-dlp&quot; target=&quot;_blank&quot;&gt;Endpoint Data Loss Protection (DLP)&lt;/a&gt; was enabled for a user before the user enrolled in Zscaler Client Connector.&lt;/li&gt;&lt;li data-list-item-id=&quot;e33600ef46ccc8fcb49c9103192a9028e&quot;&gt;Fixes an issue where Authentication Service users received an &lt;code&gt;Inconsistency in user credentials is detected&lt;/code&gt; error when reauthenticating to Private Access.&lt;/li&gt;&lt;li data-list-item-id=&quot;ea18c5f8f3abe5587c4a308e7f03f4ba7&quot;&gt;Fixes an issue where Zscaler Client Connector could experience frequent disconnections on devices with another application that modifies OpenSSL environment variables when &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/supported-parameters-zscaler-client-connector-windows&quot; target=&quot;_blank&quot;&gt;FIPS-compliant libraries are enabled&lt;/a&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;e83e023c46825bfbf924711c6572eb5b3&quot;&gt;Fixes an issue where Zscaler Client Connector didn&#039;t connect to the &lt;a href=&quot;https://help.zscaler.com/zpa/about-vpn-service-edges&quot; target=&quot;_blank&quot;&gt;VPN Service Edge&lt;/a&gt; after the device woke from sleep until users clicked &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/troubleshooting-zscaler-client-connector#win&quot; target=&quot;_blank&quot;&gt;Restart Service&lt;/a&gt; in the app.&lt;/li&gt;&lt;li data-list-item-id=&quot;e205723214330b14826547686cad8595b&quot;&gt;Fixes an issue where VDI (virtual desktop infrastructures) users couldn&#039;t re-enroll in Zscaler Client Connector after performing a hardware migration on the VDI because Zscaler Client Connector didn&#039;t restore the original system proxy settings even though the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#pac-proxy&quot; target=&quot;_blank&quot;&gt;Cache System Proxy on Startup&lt;/a&gt; option was enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;e64a43d0ff74a28c6a44f142afae13dfb&quot;&gt;Fixes an issue where Zscaler Client Connector remained in a &lt;code&gt;Connecting&lt;/code&gt; state or the ZSATunnel process didn&#039;t start when running on AWS VDI environments using Windows Server 2019 or Windows Server 2022.&lt;/li&gt;&lt;li data-list-item-id=&quot;e9b23c4f6bb1dc16f1097c86b32ffdd7d&quot;&gt;Fixes an issue where Zscaler Client Connector showed the &lt;a href=&quot;https://help.zscaler.com/zpa/about-vpn-service-edges&quot; target=&quot;_blank&quot;&gt;VPN Service Edge&lt;/a&gt; as connected even after a network disconnect.&lt;/li&gt;&lt;li data-list-item-id=&quot;e3d1917c304e9ec6360aee00644e9009a&quot;&gt;Fixes an issue where Zscaler Client Connector didn&#039;t send updated host details after a customer migrated their virtual machines (VMs) to another VDI vendor, causing the Device Details section on the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/viewing-device-fingerprint-enrolled-device&quot; target=&quot;_blank&quot;&gt;Zscaler Client Connector Registered Device Details&lt;/a&gt; window to display outdated information.&lt;/li&gt;&lt;li data-list-item-id=&quot;ecd37abe4810d8940c188522d59d44414&quot;&gt;Fixes an issue where some applications could load slowly due to Zscaler Client Connector delays when rejecting invalid requests to the loopback proxy server.&lt;/li&gt;&lt;li data-list-item-id=&quot;e9f70d2f968aeae486701810489418d00&quot;&gt;Fixes an issue where, if the Windows certificate store included an unsupported certificate, the app disappeared from the system tray and Zscaler Client Connector consumed excessive memory.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.9.0.465</version>
                                                <pubDate>Mon, 31 Aug 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1543071 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.10 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=Windows&amp;applicable_version=4.10&amp;deployment_date=2026-08-14&amp;id=1542737</link>
                <description>&lt;p&gt;Enables automatic installation of the endpoint software used with Endpoint AI Security through Zscaler Client Connector. To learn more, contact your Zscaler Account team.&lt;/p&gt;</description>
                <category>Release in Limited Availability</category>
                                    <version>4.10</version>
                                                <pubDate>Fri, 14 Aug 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1542737 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.8.0.291 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=Windows&amp;applicable_version=4.8.0.291&amp;deployment_date=2026-08-14&amp;id=1542718</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;e3b1be5b1dc453cd92b1a8484a27984a1&quot;&gt;Updates the Zscaler Client Connector installer to include mitigation logic (previously released in a separate tool) to address upgrades to this version from earlier versions that were affected by the rare timing-dependent conditions that could cause a Windows system crash (blue screen).&lt;/li&gt;&lt;li data-list-item-id=&quot;e63cdd1e3153e2f60a528ac111ed9df12&quot;&gt;Fixes high CPU usage due to an issue with captive portal detection that occurred when Zscaler Client Connector failed to resolve or connect through the local proxy.&lt;/li&gt;&lt;li data-list-item-id=&quot;ec60e2e09e145508e5a6fe28252c3e7f1&quot;&gt;Fixes an issue where Zscaler Client Connector didn’t send the platform variable to Private Access for Authentication Service tenants, causing issues with policies based on the platform and with App Scaling.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.8.0.291</version>
                                                <pubDate>Fri, 14 Aug 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1542718 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.9.0.455 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=Windows&amp;applicable_version=4.9.0.455&amp;deployment_date=2026-08-14&amp;id=1542717</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;ebc6fbbfa86f66a8ffdd8ef9a584c6ab1&quot;&gt;Updates the Zscaler Client Connector installer to include mitigation logic (previously released in a separate tool) to address upgrades to this version from earlier versions that were affected by the rare timing-dependent conditions that could cause a Windows system crash (blue screen).&lt;/li&gt;&lt;li data-list-item-id=&quot;e4e8c145291d2b1a0e4bbf6076d4395fc&quot;&gt;Fixes an issue where the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-device-posture-profiles#Firewall&quot; target=&quot;_blank&quot;&gt;Firewall device posture check&lt;/a&gt; failed if any firewall profile had been disabled by a GPO policy even if another profile was enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;eee6cb72138cb22887b11ffd6bef5438b&quot;&gt;Fixes high CPU usage due to an issue with captive portal detection that occurred when Zscaler Client Connector failed to resolve or connect through the local proxy.&lt;/li&gt;&lt;li data-list-item-id=&quot;e68fbef0f4c3fbf948beb43c94fedc1e8&quot;&gt;Fixes an issue where Zscaler Client Connector didn’t send the platform variable to Private Access for Authentication Service tenants, causing issues with policies based on the platform and with App Scaling.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.9.0.455</version>
                                                <pubDate>Fri, 14 Aug 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1542717 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.7.0.364 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=Windows&amp;applicable_version=4.7.0.364&amp;deployment_date=2026-08-03&amp;id=1542239</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;eeb7e0c8491ff8998a003945ea537916c&quot;&gt;Supports using the ind.zscalertwo.net subcloud in the cloudName installation parameter for Zscaler Client Connector deployments in India.&lt;/li&gt;&lt;li data-list-item-id=&quot;e9cdc3d041cff23775b8e2a1ae1bd2c46&quot;&gt;Fixes an issue where Private Access reauthentication was delayed or displayed a blank login page when using &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/using-webview2-authentication&quot; target=&quot;_blank&quot;&gt;WebView2 authentication&lt;/a&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;e455be3514d58694d8570910a17deb971&quot;&gt;Fixes an issue where Zscaler Client Connector continuously tried re-registering Private Access if the first attempt failed due to a SAML token request failure (e.g., an expired identity JWT) instead of retrying the token request.&lt;/li&gt;&lt;li data-list-item-id=&quot;e4c6af7e1f01fd6fb12eced2189f6f04f&quot;&gt;Fixes an issue where, if &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#firewall&quot; target=&quot;_blank&quot;&gt;Block All Inbound Traffic&lt;/a&gt; was enabled, Zscaler Client Connector blocked loopback traffic.&lt;/li&gt;&lt;li data-list-item-id=&quot;e6228039ba655eefed4037db10a635586&quot;&gt;Fixes an issue where, if &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#zcc-fail-close-settings&quot; target=&quot;_blank&quot;&gt;Lockdown on Firewall Error&lt;/a&gt; was enabled and Zscaler Client Connector went into network lockdown, Zscaler Client Connector still blocked access after switching to a trusted network that did not require lockdown.&lt;/li&gt;&lt;li data-list-item-id=&quot;e34662eb1999b0e08d75ec345de1e4cfc&quot;&gt;Updates the ZEP (Zscaler Endpoint Protection) installer that installs &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/anti-tampering-zscaler-client-connector&quot; target=&quot;_blank&quot;&gt;anti-tampering protection&lt;/a&gt; to mitigate a security vulnerability that could allow code injections.&lt;/li&gt;&lt;li data-list-item-id=&quot;e418abfcc8ac54abd89056c1466033189&quot;&gt;Fixes an issue where DNS traffic could loop when using F5 VPN and Zscaler Client Connector over Zscaler Tunnel (Z-Tunnel) 2.0 concurrently even when the F5 DNS process (F5FltSrv.exe) was added to the process-based bypass list.&lt;/li&gt;&lt;li data-list-item-id=&quot;eef126ae8671ca43f44c79302ac85e5ed&quot;&gt;Fixes an issue that caused some DNS requests to bypass the Zscaler Tunnel (Z-Tunnel) after reusing a UDP source port from a prior TCP connection.&lt;/li&gt;&lt;li data-list-item-id=&quot;e4003da1f04874b11ff4d68895bdd347f&quot;&gt;Fixes an issue where the installation process could fail when installing Zscaler Client Connector with anti-tampering through the CLI, leaving the app partially installed and resulting in errors when trying to uninstall the app.&lt;/li&gt;&lt;li data-list-item-id=&quot;e86f5705320f56c86e7f4ecfa50926dbb&quot;&gt;Fixes a port mismatch that caused a connection problem between Zscaler Client Connector and the device, resulting in incorrect Digital Experience (ZDX) data for the user.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.7.0.364</version>
                                                <pubDate>Mon, 03 Aug 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1542239 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.8.0.284 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=Windows&amp;applicable_version=4.8.0.284&amp;deployment_date=2026-08-03&amp;id=1542238</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;ef57446f73004c535c6b0f1c5414797ce&quot;&gt;Supports using the ind.zscalertwo.net subcloud in the cloudName installation parameter for Zscaler Client Connector deployments in India.&lt;/li&gt;&lt;li data-list-item-id=&quot;e509f6bea62832f65bfa9e79553ae39f1&quot;&gt;Fixes an issue where Private Access reauthentication was delayed or displayed a blank login page when using &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/using-webview2-authentication&quot; target=&quot;_blank&quot;&gt;WebView2 authentication&lt;/a&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;efe6aa11beb2e5d3500b6cbb92f01e270&quot;&gt;Fixes an issue where Zscaler Client Connector continuously tried re-registering Private Access if the first attempt failed due to a SAML token request failure (e.g., an expired identity JWT) instead of retrying the token request.&lt;/li&gt;&lt;li data-list-item-id=&quot;e5e6f1429626ba4c14e1d0c910c0c4dc2&quot;&gt;Fixes an issue where notifications from the Zscaler Notification Framework were brought into focus even though the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#notification&quot; target=&quot;_blank&quot;&gt;Bring Notification to Focus&lt;/a&gt; option was disabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;e556e1fafd827f33e599fa25f1acc3ace&quot;&gt;Fixes an issue where, if &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#firewall&quot; target=&quot;_blank&quot;&gt;Block All Inbound Traffic&lt;/a&gt; was enabled, Zscaler Client Connector blocked loopback traffic.&lt;/li&gt;&lt;li data-list-item-id=&quot;e73bbf12e496e620f457f450ef5decbc2&quot;&gt;Fixes an issue where, if &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#zcc-fail-close-settings&quot; target=&quot;_blank&quot;&gt;Lockdown on Firewall Error&lt;/a&gt; was enabled and Zscaler Client Connector went into network lockdown, Zscaler Client Connector still blocked access after switching to a trusted network that did not require lockdown.&lt;/li&gt;&lt;li data-list-item-id=&quot;e11165762d3e4ef1b65e4efea99c8c1d7&quot;&gt;Updates the ZEP (Zscaler Endpoint Protection) installer that installs &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/anti-tampering-zscaler-client-connector&quot; target=&quot;_blank&quot;&gt;anti-tampering protection&lt;/a&gt; to mitigate a security vulnerability that could allow code injections.&lt;/li&gt;&lt;li data-list-item-id=&quot;e0963a04c70dc0082544d9ff8c9045739&quot;&gt;Fixes an issue where file uploads using WinSCP (Windows Secure Copy) became progressively slower when connecting to an FTP-SFTP server using Private Access.&lt;/li&gt;&lt;li data-list-item-id=&quot;ecbd4d57d8310028ee47c69ae046ac61f&quot;&gt;Fixes an issue that caused some DNS requests to bypass the Zscaler Tunnel (Z-Tunnel) after reusing a UDP source port from a prior TCP connection.&lt;/li&gt;&lt;li data-list-item-id=&quot;ef5f02296989439cabbfe15ea46e23a0a&quot;&gt;Fixes an issue where the installation process could fail when installing Zscaler Client Connector with anti-tampering through the CLI, leaving the app partially installed and resulting in errors when trying to uninstall the app.&lt;/li&gt;&lt;li data-list-item-id=&quot;e3dc73e3d9969fc151c7316e3dd86fcec&quot;&gt;Fixes an issue where, after switching from a machine tunnel to a user tunnel, access to Private Access applications was denied due to a timing issue that prevented successful posture results from being delivered.&lt;/li&gt;&lt;li data-list-item-id=&quot;e08d7a950b11b3770724cd353485b737d&quot;&gt;Fixes a port mismatch that caused a connection problem between Zscaler Client Connector and the device, resulting in incorrect Digital Experience (ZDX) data for the user.&lt;/li&gt;&lt;li data-list-item-id=&quot;e3f8a73f04ca9b0664e9c4158ffb94836&quot;&gt;Fixes an issue where Zscaler Client Connector displayed the default notification after a transaction was blocked by a Data Loss Prevention (DLP) policy rule instead of the notification from the &lt;a href=&quot;https://help.zscaler.com/zia/configuring-dlp-notification-templates&quot; target=&quot;_blank&quot;&gt;DLP template&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.8.0.284</version>
                                                <pubDate>Mon, 03 Aug 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1542238 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.9.0.448 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=Windows&amp;applicable_version=4.9.0.448&amp;deployment_date=2026-08-03&amp;id=1542167</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;ef945fd08a4fb60f5c4f7a6d480e3dadc&quot;&gt;Supports using the ind.zscalertwo.net subcloud in the cloudName installation parameter for Zscaler Client Connector deployments in India.&lt;/li&gt;&lt;li data-list-item-id=&quot;e7bd5658b0fdbbea3636f12cff4ce93d7&quot;&gt;Fixes an issue where Private Access reauthentication was delayed or displayed a blank login page when using &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/using-webview2-authentication&quot; target=&quot;_blank&quot;&gt;WebView2 authentication&lt;/a&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;e7b737b19145ab45b434a1f8f32849e5e&quot;&gt;Fixes an issue where Zscaler Client Connector continuously tried re-registering Private Access if the first attempt failed due to a SAML token request failure (e.g., an expired identity JWT) instead of retrying the token request.&lt;/li&gt;&lt;li data-list-item-id=&quot;e7fe3efe52d79dba8d11c3b5ada6756c4&quot;&gt;Fixes an issue where notifications from the Zscaler Notification Framework were brought into focus even though the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#notification&quot; target=&quot;_blank&quot;&gt;Bring Notification to Focus&lt;/a&gt; option was disabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;e6c5d475aabc6a2692258e7ae9a6d43fc&quot;&gt;Fixes an issue where, if &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#firewall&quot; target=&quot;_blank&quot;&gt;Block All Inbound Traffic&lt;/a&gt; was enabled, Zscaler Client Connector blocked loopback traffic.&lt;/li&gt;&lt;li data-list-item-id=&quot;e5a99e6f1e1ead57e0cb18a1e1b59ef18&quot;&gt;Fixes an issue where, if &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#zcc-fail-close-settings&quot; target=&quot;_blank&quot;&gt;Lockdown on Firewall Error&lt;/a&gt; was enabled and Zscaler Client Connector went into network lockdown, Zscaler Client Connector still blocked access after switching to a trusted network that did not require lockdown.&lt;/li&gt;&lt;li data-list-item-id=&quot;e09657078007ad8a2f456897a3bdd079e&quot;&gt;Updates the ZEP (Zscaler Endpoint Protection) installer that installs &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/anti-tampering-zscaler-client-connector&quot; target=&quot;_blank&quot;&gt;anti-tampering protection&lt;/a&gt; to mitigate a security vulnerability that could allow code injections.&lt;/li&gt;&lt;li data-list-item-id=&quot;eb87ef3de8ac56f0d76088fea00ccf667&quot;&gt;Fixes an issue where fragmented packet handling in Zscaler Client Connector could cause the tunnel service to become unresponsive and temporarily disrupt network connectivity.&lt;/li&gt;&lt;li data-list-item-id=&quot;e9015fed5ae502cecb01af2aafc38128a&quot;&gt;Fixes an issue where users couldn’t access Private Access resources when the DNS responses, such as SRV (Service) records, were large and occasionally became fragmented.&lt;/li&gt;&lt;li data-list-item-id=&quot;e22334612a16b2d3ba730c67fb4ab7426&quot;&gt;Fixes an issue where file uploads using WinSCP (Windows Secure Copy) became progressively slower when connecting to an FTP-SFTP server using Private Access.&lt;/li&gt;&lt;li data-list-item-id=&quot;e28c8d8e5009085f99d72613cfb2e3fcd&quot;&gt;Fixes a Windows registry value to prevent unquoted service path enumeration.&lt;/li&gt;&lt;li data-list-item-id=&quot;ebeccd7cdffc310bcaea0f47bf6819bb6&quot;&gt;Fixes an issue that caused some DNS requests to bypass the Zscaler Tunnel (Z-Tunnel) after reusing a UDP source port from a prior TCP connection.&lt;/li&gt;&lt;li data-list-item-id=&quot;e1730eab95ff3d5522f607ac5018ef465&quot;&gt;Fixes an issue where DNS lookups could intermittently fail during failover to the &lt;a href=&quot;https://help.zscaler.com/zpa/configuring-network-segments&quot; target=&quot;_blank&quot;&gt;secondary DNS server&lt;/a&gt; due to IPv6 behavior in the VPN (for Legacy Apps).&lt;/li&gt;&lt;li data-list-item-id=&quot;e844feed7c007f879985881ca9ecb9d2a&quot;&gt;Fixes an issue where the installation process could fail when installing Zscaler Client Connector with anti-tampering through the CLI, leaving the app partially installed and resulting in errors when trying to uninstall the app.&lt;/li&gt;&lt;li data-list-item-id=&quot;e07aac1b3f980ecfcb4f774d4569ea5be&quot;&gt;Fixes an issue where, after switching from a machine tunnel to a user tunnel, access to Private Access applications was denied due to a timing issue that prevented successful posture results from being delivered.&lt;/li&gt;&lt;li data-list-item-id=&quot;e79e9ad2770272c020c4208f5e32abd6c&quot;&gt;Fixes a port mismatch that caused a connection problem between Zscaler Client Connector and the device, resulting in incorrect Digital Experience (ZDX) data for the user.&lt;/li&gt;&lt;li data-list-item-id=&quot;ed6e2e5c7ad0dbf9eac76ff7da957f8e7&quot;&gt;Fixes an issue where Zscaler Client Connector displayed the default notification after a transaction was blocked by a Data Loss Prevention (DLP) policy rule instead of the notification from the &lt;a href=&quot;https://help.zscaler.com/zia/configuring-dlp-notification-templates&quot; target=&quot;_blank&quot;&gt;DLP template&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.9.0.448</version>
                                                <pubDate>Mon, 03 Aug 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1542167 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.8.0.267 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=Windows&amp;applicable_version=4.8.0.267&amp;deployment_date=2026-07-01&amp;id=1541441</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;e95f3c2ebdb4dc884def5873540933143&quot;&gt;Fixes an issue when using an SCCM virtual adapter where DNS responses for Zscaler Private Access (ZPA) applications could be delayed after switching networks if the &lt;a href=&quot;https://help.zscaler.com/zpa/adding-ip-ranges&quot; target=&quot;_blank&quot;&gt;Send Location Hint to Client Connecto&lt;/a&gt;r option was enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;e341c81b564d584877772bf4909ece89d&quot;&gt;Fixes an issue where Zscaler Client Connector disabled hardware offloading features in the LWF driver, even though &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#adv&quot; target=&quot;_blank&quot;&gt;Adapter Hardware Offloading&lt;/a&gt; was enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;e82f7116071d59b1c45bbefe20cbf723c&quot;&gt;Fixes an issue where the Zscaler Client Connector filter driver interaction with the Wi-Fi Direct virtual adapter caused internet connectivity to drop when using Miracast screen mirroring.&lt;/li&gt;&lt;li data-list-item-id=&quot;ef4b1cab08a2a0357add64bb3206eedb9&quot;&gt;Updates the network interface retrieval process for the LWF driver to clear temporary kernel buffer data to prevent data leakage.&lt;/li&gt;&lt;li data-list-item-id=&quot;e66440e1f4246d37b8a31faa8fbf47fcc&quot;&gt;Fixes an issue where users received a &lt;code&gt;Chaining Authentication Error&lt;/code&gt; message if a manual policy update happened at the same time as a periodic policy update until they resolved the issue by updating the policy or restarting the Zscaler service.&lt;/li&gt;&lt;li data-list-item-id=&quot;e3e1841bd890f0c9b7fed739028e7ed66&quot;&gt;Updates the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-forwarding-profiles-zscaler-client-connector#advanced-z-tunnel-config&quot; target=&quot;_blank&quot;&gt;Enable DTLS Instability Detection and Fallback&lt;/a&gt; option to improve response time when falling back to TLS after DTLS performance deteriorates.&lt;/li&gt;&lt;li data-list-item-id=&quot;e4f98adccd49375e5505b241c9597bdab&quot;&gt;Fixes an issue with slow throughput that occurred when accessing an SMB (Server Message Block) file share through an app segment with the &lt;a href=&quot;https://help.zscaler.com/zpa/configuring-defined-application-segments#define-clientconnector&quot; target=&quot;_blank&quot;&gt;Double Encryption&lt;/a&gt; option enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;e6dbf7e119257bf48dc4467a3f10c70a6&quot;&gt;Fixes an issue where the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/viewing-device-fingerprint-enrolled-device&quot; target=&quot;_blank&quot;&gt;Disable ZIA OTP, Disable ZPA OTP, and Logout OTP&lt;/a&gt; one-time passwords failed for customers using Authentication Service due to a server and app password mismatch that occurred after registration.&lt;/li&gt;&lt;li data-list-item-id=&quot;e27b24e60fe0828851eaeb0f333454a10&quot;&gt;Fixes an issue where, when the forwarding profile wasn&#039;t set to &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-forwarding-profiles-zscaler-client-connector#enforce-proxy&quot; target=&quot;_blank&quot;&gt;Enforce Proxy&lt;/a&gt;, Zscaler Client Connector removed the system proxy after exiting the app.&lt;/li&gt;&lt;li data-list-item-id=&quot;ec07534868ae731e850acb3edd5eed083&quot;&gt;Fixes an issue where Zscaler Client Connector remained in an On-Trusted Network after the device woke from standby or sleep mode, even if the network had changed.&lt;/li&gt;&lt;li data-list-item-id=&quot;e01f96d5562e287264b0f5b1acc17790b&quot;&gt;Upgrades the version of SQLite used by Zscaler Client Connector to SQLite version 3.53.1.&lt;/li&gt;&lt;li data-list-item-id=&quot;e5d20e81a3dcec777848d6567e3889284&quot;&gt;Fixes an issue where users were prompted to reauthenticate ZPA even though ZPA was disabled on the network based on the network criteria.&lt;/li&gt;&lt;li data-list-item-id=&quot;e2e00dc75dd7c69ff82fba3954569bd83&quot;&gt;Updates the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/enforcing-secure-pac-urls&quot; target=&quot;_blank&quot;&gt;Enforce Secure PAC URLs&lt;/a&gt; feature to normalize HTTP URLs to HTTPS and to limit HTTP fallback.&lt;/li&gt;&lt;li data-list-item-id=&quot;e0fea696baeb19a52425293b929021045&quot;&gt;Fixes an issue in the ZPA tunnel which could lead to a race condition. (CVE-2026-25687)&lt;/li&gt;&lt;li data-list-item-id=&quot;e940b58f3f08c5291a5676aead20f135a&quot;&gt;Fixes an issue where traffic was temporarily sent to the gateway domain after Zscaler Tunnel (Z-Tunnel) 2.0 startup instead of the proxy in the forwarding PAC file.&lt;/li&gt;&lt;li data-list-item-id=&quot;e3b35713a0e067456d1334054a1c8b01d&quot;&gt;Fixes an issue where posture checks weren’t evaluated correctly for a partner if the domain of the partner tenant is on a different cloud than the main tenant.&lt;/li&gt;&lt;li data-list-item-id=&quot;eb658ca9385a3bcd9f49cee3f460a46cd&quot;&gt;Fixes duplicate requests that could cause a &lt;code&gt;There was an error starting Private Access&lt;/code&gt; error message after a logged-in partner tenant exited and relaunched the app.&lt;/li&gt;&lt;li data-list-item-id=&quot;edab354bbab08b4e19764882cadbac7cc&quot;&gt;Fixes an issue where, when switching from a LAN to Wi-Fi or between Wi-Fi networks, Zscaler Client Connector incorrectly entered a &lt;code&gt;ServerDown&lt;/code&gt; state which could cause traffic to briefly go direct if the forwarding profile or fail-open settings are set to not block traffic if the Service Edge isn&#039;t reachable.&lt;/li&gt;&lt;li data-list-item-id=&quot;e82d5173d83b18261d1b21b123f9a8b2b&quot;&gt;Fixes an issue when using an SCCM virtual adapter where a tunnel crash could occur after traffic forwarding for ZPA switched and the &lt;a href=&quot;https://help.zscaler.com/zpa/adding-ip-ranges&quot; target=&quot;_blank&quot;&gt;Send Location Hint to Client Connecto&lt;/a&gt;r option was enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;e64ce90d9a8fd5e4e89a986f7a3dafd45&quot;&gt;Fixes an issue where the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-device-posture-profiles#Client-Certificate&quot; target=&quot;_blank&quot;&gt;Client Certificate&lt;/a&gt; device posture check wasn’t evaluated correctly for a partner tenant.&lt;/li&gt;&lt;li data-list-item-id=&quot;e534b0d61f08cb9dbbced971c7c8ec735&quot;&gt;Fixes an issue where Zscaler Client Connector didn’t apply the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#firewall&quot; target=&quot;_blank&quot;&gt;Block All Inbound Traffic&lt;/a&gt; firewall settings correctly after a policy update.&lt;/li&gt;&lt;li data-list-item-id=&quot;e087accf03f5c1ee554739d8e5734a7bf&quot;&gt;Fixes an issue with the fail-close, application bypass, block domain profile detection, and captive portal lockdown features that could cause a tunnel crash.&lt;/li&gt;&lt;li data-list-item-id=&quot;e1e8d41d6a3e27d3f95d8cd48d2525606&quot;&gt;Fixes an issue where, if the primary DNS server returned NXDOMAIN (Non-Existent Domain) and the secondary DNS server failed, Zscaler Client Connector stayed on an On-Trusted Network and didn&#039;t switch to an Off-Trusted Network.&lt;/li&gt;&lt;li data-list-item-id=&quot;e5685e27af8069f52b0e28fae43b04d0f&quot;&gt;Fixes an issue where, in a no-default route environment, policy updates were sent directly instead of through the tunnel even though &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#advanced&quot; target=&quot;_blank&quot;&gt;Tunnel Internal Client Connector Traffic&lt;/a&gt; was enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;e4c5bffe0c1645ba87644ff8202f141f5&quot;&gt;Fixes an issue where Acceptable Use Policy (AUP) data was reset during ZPA reauthentication, resulting in ZPA entitlement being removed for multiple users.&lt;/li&gt;&lt;li data-list-item-id=&quot;e22a119fd0b07a86a696afbbf34a8e5dd&quot;&gt;Fixes an issue where, for devices authenticating with an IdP as a ZPA app segment and using the machine tunnel on a network identified by Trusted Network Criteria, first-time enrollment failed during ZPA registration if the app profile had &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#Business_Continuity&quot; target=&quot;_blank&quot;&gt;business continuity&lt;/a&gt; enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;e7b6b86f437d59bac676ff59e70bcdfa5&quot;&gt;Fixes an issue where VPN Service Edge tunnel connections intermittently failed or dropped after logging off and then logging back in to Windows.&lt;/li&gt;&lt;li data-list-item-id=&quot;eb04a35eda07cfdd7082fd7aff71b3f02&quot;&gt;Updates the network detection process to treat network detection failures as being on an Off-Trusted Network to prevent devices from remaining in an On-Trusted Network state if DNS hostname resolution is delayed.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.8.0.267</version>
                                                <pubDate>Wed, 01 Jul 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1541441 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.6.0.486 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=Windows&amp;applicable_version=4.6.0.486&amp;deployment_date=2026-06-30&amp;id=1541403</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;ea7a05330a1a5e25f29d760366a6a2dcd&quot;&gt;Fixes an issue where the Zscaler Client Connector filter driver interaction with the Wi-Fi Direct virtual adapter caused internet connectivity to drop when using Miracast screen mirroring.&lt;/li&gt;&lt;li data-list-item-id=&quot;ec7b51796e99d385a9e6c298a5c72ed7c&quot;&gt;Updates the network interface retrieval process for the LWF driver to clear temporary kernel buffer data to prevent data leakage.&lt;/li&gt;&lt;li data-list-item-id=&quot;e35246e256d9a73214991a601dc71e9dc&quot;&gt;Fixes an issue where users received a &lt;code&gt;Chaining Authentication Error&lt;/code&gt; message if a manual policy update happened at the same time as a periodic policy update until they resolved the issue by updating the policy or restarting the Zscaler service.&lt;/li&gt;&lt;li data-list-item-id=&quot;e9c974aa94332ded6939ebdab8859fb5f&quot;&gt;Fixes an issue where, when using &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-forwarding-profiles-zscaler-client-connector#tunnel&quot; target=&quot;_blank&quot;&gt;Dynamic ZIA Service Edge Assignment&lt;/a&gt;, Zscaler Client Connector didn’t display a user notification that the Service Edge had switched if the switch happened before the dynamic probes detected the issue.&lt;/li&gt;&lt;li data-list-item-id=&quot;e08bed3dea300f315ce8f3826bf30c28e&quot;&gt;Fixes an issue where the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/viewing-device-fingerprint-enrolled-device&quot; target=&quot;_blank&quot;&gt;Disable ZIA OTP, Disable ZPA OTP, and Logout OTP&lt;/a&gt; one-time passwords failed for customers using Authentication Service due to a server and app password mismatch that occurred after registration.&lt;/li&gt;&lt;li data-list-item-id=&quot;e9c5f44923b1c69e66f85d3bb39806aa4&quot;&gt;Upgrades the version of SQLite used by Zscaler Client Connector to SQLite version 3.53.1.&lt;/li&gt;&lt;li data-list-item-id=&quot;e595a2e234e7510cfcd93ad80c69709d0&quot;&gt;Fixes an issue in the Zscaler Private Access (ZPA) tunnel which could lead to a race condition. (CVE-2026-25687)&lt;/li&gt;&lt;li data-list-item-id=&quot;e4396f28e3cbe7cff6af091d2a87d0994&quot;&gt;Updates the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/enforcing-secure-pac-urls&quot; target=&quot;_blank&quot;&gt;Enforce Secure PAC URLs&lt;/a&gt; feature to normalize HTTP URLs to HTTPS and to limit HTTP fallback.&lt;/li&gt;&lt;li data-list-item-id=&quot;e1a6a3e851457a4c2842d94e9048c8888&quot;&gt;Fixes duplicate requests that could cause a &lt;code&gt;There was an error starting Private Access&lt;/code&gt; error message after a logged-in partner tenant exited and relaunched the app.&lt;/li&gt;&lt;li data-list-item-id=&quot;e553bcc686f6b25a6b207333d303eceaa&quot;&gt;Fixes an issue where the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-device-posture-profiles#Client-Certificate&quot; target=&quot;_blank&quot;&gt;Client Certificate&lt;/a&gt; device posture check wasn’t evaluated correctly for a partner tenant.&lt;/li&gt;&lt;li data-list-item-id=&quot;eb238d3acd9428f1771e99ef09d913a5b&quot;&gt;Fixes an issue where, in a no-default route environment, policy updates were sent directly instead of through the tunnel even though &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#advanced&quot; target=&quot;_blank&quot;&gt;Tunnel Internal Client Connector Traffic&lt;/a&gt; was enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;e321e0eecefdcf2df69b97988e22368e1&quot;&gt;Fixes an issue where the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-device-posture-profiles#Full-Disk-Encryption&quot; target=&quot;_blank&quot;&gt;Full Disk Encryption&lt;/a&gt; device posture check could pass while BitLocker protection was suspended on the device.&lt;/li&gt;&lt;li data-list-item-id=&quot;e7223ad23770d1932c3e1625ef264a590&quot;&gt;Fixes an issue where VPN Service Edge tunnel connections intermittently failed or dropped after logging off and then logging back in to Windows.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.6.0.486</version>
                                                <pubDate>Tue, 30 Jun 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1541403 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.7.0.350 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=Windows&amp;applicable_version=4.7.0.350&amp;deployment_date=2026-06-30&amp;id=1541480</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;ee7d191701161daa48c68e7cb468764c3&quot;&gt;Fixes an issue when using an SCCM virtual adapter where DNS responses for Zscaler Private Access (ZPA) applications could be delayed after switching networks if the &lt;a href=&quot;https://help.zscaler.com/zpa/adding-ip-ranges&quot; target=&quot;_blank&quot;&gt;Send Location Hint to Client Connecto&lt;/a&gt;r option was enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;e16d818d3e8f8113cac8bfcf40d2005f8&quot;&gt;Fixes an issue where Zscaler Client Connector disabled hardware offloading features in the LWF driver, even though &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#adv&quot; target=&quot;_blank&quot;&gt;Adapter Hardware Offloading&lt;/a&gt; was enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;e3dce2b8ff7668ec8af0ba994325597a6&quot;&gt;Fixes an issue where the Zscaler Client Connector filter driver interaction with the Wi-Fi Direct virtual adapter caused internet connectivity to drop when using Miracast screen mirroring.&lt;/li&gt;&lt;li data-list-item-id=&quot;e688156219682a85688a3a5896e65868b&quot;&gt;Updates the network interface retrieval process for the LWF driver to clear temporary kernel buffer data to prevent data leakage.&lt;/li&gt;&lt;li data-list-item-id=&quot;efcd1da7f97daa5baee0d412435d96146&quot;&gt;Fixes an issue where the FIPS integrity check could fail for some components after installing Zscaler Client Connector, resulting in the app failing to start.&lt;/li&gt;&lt;li data-list-item-id=&quot;eaf70cf19619f64cfc9184d654f04cbe2&quot;&gt;Fixes an issue where traffic for process-based application bypasses using Certificate Subject as a matching criterion wasn&#039;t bypassed and was sent through the tunnel.&lt;/li&gt;&lt;li data-list-item-id=&quot;ed7b741fd44a1873e5477ef865b3d36c5&quot;&gt;Fixes an issue where, for users with an app profile with a &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#general&quot; target=&quot;_blank&quot;&gt;notification template&lt;/a&gt; selected, the Show All Notifications and Show Private Access Reauthentication Notification settings on the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/viewing-notifications-zscaler-client-connector&quot; target=&quot;_blank&quot;&gt;More window&lt;/a&gt; in the app weren&#039;t reset to the default values from the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-notification-templates-zscaler-client-connector&quot; target=&quot;_blank&quot;&gt;notification template&lt;/a&gt; after upgrading.&lt;/li&gt;&lt;li data-list-item-id=&quot;ea531f471fe3b1c96430369664a84e911&quot;&gt;Fixes an issue where &lt;a href=&quot;https://help.zscaler.com/zia/configuring-euns-inline-web-dlp&quot; target=&quot;_blank&quot;&gt;Inline Web DLP&lt;/a&gt; and &lt;a href=&quot;https://help.zscaler.com/zia/configuring-euns-endpoint-dlp&quot; target=&quot;_blank&quot;&gt;Endpoint DLP&lt;/a&gt; notifications weren&#039;t defined as critical, resulting in both notifications being suppressed for users with the Show notification pop-ups option disabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;e926f8b752ca0eb74d31da4c19d690986&quot;&gt;Fixes an issue where users received a &lt;code&gt;Chaining Authentication Error&lt;/code&gt; message if a manual policy update happened at the same time as a periodic policy update until they resolved the issue by updating the policy or restarting the Zscaler service.&lt;/li&gt;&lt;li data-list-item-id=&quot;ec9cd141b5da69e968973582212ce2df3&quot;&gt;Fixes an issue with slow throughput that occurred when accessing an SMB (Server Message Block) file share through an app segment with the &lt;a href=&quot;https://help.zscaler.com/zpa/configuring-defined-application-segments#define-clientconnector&quot; target=&quot;_blank&quot;&gt;Double Encryption&lt;/a&gt; option enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;eb3fdbc12af633fefedae1e4a7156e012&quot;&gt;Fixes an issue where, when using &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-forwarding-profiles-zscaler-client-connector#tunnel&quot; target=&quot;_blank&quot;&gt;Dynamic ZIA Service Edge Assignment&lt;/a&gt;, Zscaler Client Connector didn’t display a user notification that the Service Edge had switched if the switch happened before the dynamic probes detected the issue.&lt;/li&gt;&lt;li data-list-item-id=&quot;edd8993218098312c9d1917fa79e1de72&quot;&gt;Fixes an issue where the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/viewing-device-fingerprint-enrolled-device&quot; target=&quot;_blank&quot;&gt;Disable ZIA OTP, Disable ZPA OTP, and Logout OTP&lt;/a&gt; one-time passwords failed for customers using Authentication Service due to a server and app password mismatch that occurred after registration.&lt;/li&gt;&lt;li data-list-item-id=&quot;e479f1c64eb64ee221fbf21fa36cedf40&quot;&gt;Fixes an issue where, when the forwarding profile wasn&#039;t set to &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-forwarding-profiles-zscaler-client-connector#enforce-proxy&quot; target=&quot;_blank&quot;&gt;Enforce Proxy&lt;/a&gt;, Zscaler Client Connector removed the system proxy after exiting the app.&lt;/li&gt;&lt;li data-list-item-id=&quot;e561e96bd694d0b38f4849a413819204b&quot;&gt;Fixes an issue where Zscaler Client Connector remained in an On-Trusted Network after the device woke from standby or sleep mode, even if the network had changed.&lt;/li&gt;&lt;li data-list-item-id=&quot;e67cf9bace5ba684024b70ee4c2a2f293&quot;&gt;Upgrades the version of SQLite used by Zscaler Client Connector to SQLite version 3.53.1.&lt;/li&gt;&lt;li data-list-item-id=&quot;ee26b7b1869c2a585a2d05d67c0bb4a80&quot;&gt;Fixes an issue where users were prompted to reauthenticate ZPA even though ZPA was disabled on the network based on the network criteria.&lt;/li&gt;&lt;li data-list-item-id=&quot;ebdba9d9fa16a9181784efa1b0dcfb913&quot;&gt;Updates the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/enforcing-secure-pac-urls&quot; target=&quot;_blank&quot;&gt;Enforce Secure PAC URLs&lt;/a&gt; feature to normalize HTTP URLs to HTTPS and to limit HTTP fallback.&lt;/li&gt;&lt;li data-list-item-id=&quot;e7ea81b7c834e83b0eed42788de0edbf0&quot;&gt;Fixes an issue in the ZPA tunnel which could lead to a race condition. (CVE-2026-25687)&lt;/li&gt;&lt;li data-list-item-id=&quot;ea354d7e3d0f0fd30bdff78c750c3fd3c&quot;&gt;Fixes an issue where traffic was temporarily sent to the gateway domain after Zscaler Tunnel (Z-Tunnel) 2.0 startup instead of the proxy in the forwarding PAC file.&lt;/li&gt;&lt;li data-list-item-id=&quot;ef744a1d76b0959353e5dea7f9f31e78b&quot;&gt;Fixes an issue where posture checks weren’t evaluated correctly for a partner if the domain of the partner tenant is on a different cloud than the main tenant.&lt;/li&gt;&lt;li data-list-item-id=&quot;ea2755f2d3c8f23c8ecec5d493d53fd38&quot;&gt;Fixes duplicate requests that could cause a &lt;code&gt;There was an error starting Private Access&lt;/code&gt; error message after a logged-in partner tenant exited and relaunched the app.&lt;/li&gt;&lt;li data-list-item-id=&quot;e661f42bd8da5be99e6c4ea5755d7e8c8&quot;&gt;Fixes an issue where, when switching from a LAN to Wi-Fi or between Wi-Fi networks, Zscaler Client Connector incorrectly entered a &lt;code&gt;ServerDown&lt;/code&gt; state which could cause traffic to briefly go direct if the forwarding profile or fail-open settings are set to not block traffic if the Service Edge isn&#039;t reachable.&lt;/li&gt;&lt;li data-list-item-id=&quot;ef943d823eb038828917287bfe0108a47&quot;&gt;Fixes an issue when using an SCCM virtual adapter where a tunnel crash could occur after traffic forwarding for ZPA switched and the &lt;a href=&quot;https://help.zscaler.com/zpa/adding-ip-ranges&quot; target=&quot;_blank&quot;&gt;Send Location Hint to Client Connecto&lt;/a&gt;r option was enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;ea9e261680ef66827ef8ad024084accde&quot;&gt;Fixes an issue where the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-device-posture-profiles#Client-Certificate&quot; target=&quot;_blank&quot;&gt;Client Certificate&lt;/a&gt; device posture check wasn’t evaluated correctly for a partner tenant.&lt;/li&gt;&lt;li data-list-item-id=&quot;ef5a3778df01ffffa46bfceacd3bd6197&quot;&gt;Fixes an issue where Zscaler Client Connector didn’t apply the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#firewall&quot; target=&quot;_blank&quot;&gt;Block All Inbound Traffic&lt;/a&gt; firewall settings correctly after a policy update.&lt;/li&gt;&lt;li data-list-item-id=&quot;edbc9f215602f306e4f66b85e72641aee&quot;&gt;Fixes an issue with the fail-close, application bypass, block domain profile detection, and captive portal lockdown features that could cause a tunnel crash.&lt;/li&gt;&lt;li data-list-item-id=&quot;e95046d74dabd58115e5e8ee683f16940&quot;&gt;Fixes an issue where, if the primary DNS server returned NXDOMAIN (Non-Existent Domain) and the secondary DNS server failed, Zscaler Client Connector stayed on an On-Trusted Network and didn&#039;t switch to an Off-Trusted Network.&lt;/li&gt;&lt;li data-list-item-id=&quot;e9e125142c3b04acff5fb952d1890728c&quot;&gt;Fixes an issue where, in a no-default route environment, policy updates were sent directly instead of through the tunnel even though &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#advanced&quot; target=&quot;_blank&quot;&gt;Tunnel Internal Client Connector Traffic&lt;/a&gt; was enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;efc7a2ea5dbbc27b510fcf53abbd476da&quot;&gt;Fixes an issue where the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-device-posture-profiles#Full-Disk-Encryption&quot; target=&quot;_blank&quot;&gt;Full Disk Encryption&lt;/a&gt; device posture check could pass while BitLocker protection was suspended on the device.&lt;/li&gt;&lt;li data-list-item-id=&quot;eddbc5bf7c3be4ffb1e517ecb1445f256&quot;&gt;Fixes an issue where, for devices authenticating with an IdP as a ZPA app segment and using the machine tunnel on a network identified by Trusted Network Criteria, first-time enrollment failed during ZPA registration if the app profile had &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#Business_Continuity&quot; target=&quot;_blank&quot;&gt;business continuity&lt;/a&gt; enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;e438be70b5e8914a25a975baaa476d083&quot;&gt;Fixes an issue where VPN Service Edge tunnel connections intermittently failed or dropped after logging off and then logging back in to Windows.&lt;/li&gt;&lt;li data-list-item-id=&quot;eb2d54af6683505604cc88bfc24fcc3b9&quot;&gt;Updates the network detection process to treat network detection failures as being on an Off-Trusted Network to prevent devices from remaining in an On-Trusted Network state if DNS hostname resolution is delayed.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.7.0.350</version>
                                                <pubDate>Tue, 30 Jun 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1541480 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.9.0.412 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=Windows&amp;applicable_version=4.9.0.412&amp;deployment_date=2026-06-30&amp;id=1541468</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;e58ee71d2b88b373ec5983ac41b2af1e2&quot;&gt;Fixes an issue where Zscaler Client Connector disabled hardware offloading features in the LWF driver, even though &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#adv&quot; target=&quot;_blank&quot;&gt;Adapter Hardware Offloading&lt;/a&gt; was enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;eb71d25e18da1b883a6d41a7d83afa3fe&quot;&gt;Fixes an issue where the Zscaler Client Connector filter driver interaction with the Wi-Fi Direct virtual adapter caused internet connectivity to drop when using Miracast screen mirroring.&lt;/li&gt;&lt;li data-list-item-id=&quot;e971c99abd7c36c8ebe8a07c730cb5cd5&quot;&gt;Fixes an intermittent issue where the LTE cellular adapter was disconnected after a driver upgrade during a Zscaler Client Connector upgrade and didn&#039;t reconnect until the user reset the adapter.&lt;/li&gt;&lt;li data-list-item-id=&quot;e64c786ec7d9ae78e562dfd1ee7a14d91&quot;&gt;Fixes an issue where users received a &lt;code&gt;Chaining Authentication Error&lt;/code&gt; message if a manual policy update happened at the same time as a periodic policy update until they resolved the issue by updating the policy or restarting the Zscaler service.&lt;/li&gt;&lt;li data-list-item-id=&quot;e7dcfe2817a8709b8a90b7e02b711feb9&quot;&gt;Updates the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-forwarding-profiles-zscaler-client-connector#advanced-z-tunnel-config&quot; target=&quot;_blank&quot;&gt;Enable DTLS Instability Detection and Fallback&lt;/a&gt; option to improve response time when falling back to TLS after DTLS performance deteriorates.&lt;/li&gt;&lt;li data-list-item-id=&quot;e10ed8f8ca595d396fddab34364aadfd5&quot;&gt;Fixes an issue with slow throughput that occurred when accessing an SMB (Server Message Block) file share through an app segment with the &lt;a href=&quot;https://help.zscaler.com/zpa/configuring-defined-application-segments#define-clientconnector&quot; target=&quot;_blank&quot;&gt;Double Encryption&lt;/a&gt; option enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;ebe7d82129b96cd2572eb15ce46373f8a&quot;&gt;Fixes an issue where the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/viewing-device-fingerprint-enrolled-device&quot; target=&quot;_blank&quot;&gt;Disable ZIA OTP, Disable ZPA OTP, and Logout OTP&lt;/a&gt; one-time passwords failed for customers using Authentication Service due to a server and app password mismatch that occurred after registration.&lt;/li&gt;&lt;li data-list-item-id=&quot;e4a6fcc69ca1cf9c24a1f00352dcba1ce&quot;&gt;Fixes an issue where, when the forwarding profile wasn&#039;t set to &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-forwarding-profiles-zscaler-client-connector#enforce-proxy&quot; target=&quot;_blank&quot;&gt;Enforce Proxy&lt;/a&gt;, Zscaler Client Connector removed the system proxy after exiting the app.&lt;/li&gt;&lt;li data-list-item-id=&quot;ec14b2042ad477caf35df7035e059ae2a&quot;&gt;Fixes an issue where Zscaler Client Connector remained in an On-Trusted Network after the device woke from standby or sleep mode, even if the network had changed.&lt;/li&gt;&lt;li data-list-item-id=&quot;e9dde9fd0093bd9f6143f5ec0a6350780&quot;&gt;Upgrades the version of SQLite used by Zscaler Client Connector to SQLite version 3.53.1.&lt;/li&gt;&lt;li data-list-item-id=&quot;e66e1a4a5d293c858c1fad832804381fc&quot;&gt;Fixes an issue where users were prompted to reauthenticate Zscaler Private Access (ZPA) even though ZPA was disabled on the network based on the network criteria.&lt;/li&gt;&lt;li data-list-item-id=&quot;ec5ca8a80a68e49314e94a2627a303bf7&quot;&gt;Updates the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/enforcing-secure-pac-urls&quot; target=&quot;_blank&quot;&gt;Enforce Secure PAC URLs&lt;/a&gt; feature to normalize HTTP URLs to HTTPS and to limit HTTP fallback.&lt;/li&gt;&lt;li data-list-item-id=&quot;e4ef3e83448685e40dd754efb5e1fdd68&quot;&gt;Fixes an issue in the ZPA tunnel which could lead to a race condition. (CVE-2026-25687)&lt;/li&gt;&lt;li data-list-item-id=&quot;e56bf2dc48815786b276bc90407c11c3e&quot;&gt;Fixes an issue where traffic was temporarily sent to the gateway domain after Zscaler Tunnel (Z-Tunnel) 2.0 startup instead of the proxy in the forwarding PAC file.&lt;/li&gt;&lt;li data-list-item-id=&quot;e73c92e184633515a6bcb972d3918ff28&quot;&gt;Fixes an issue where posture checks weren’t evaluated correctly for a partner if the domain of the partner tenant is on a different cloud than the main tenant.&lt;/li&gt;&lt;li data-list-item-id=&quot;ec6a6ca8cdffa1bc2cfe70f3904777560&quot;&gt;Fixes duplicate requests that could cause a &lt;code&gt;There was an error starting Private Access&lt;/code&gt; error message after a logged-in partner tenant exited and relaunched the app.&lt;/li&gt;&lt;li data-list-item-id=&quot;eaf97699207a4ceb9d69660ea02cce18c&quot;&gt;Fixes an issue when using an SCCM virtual adapter where a tunnel crash could occur after traffic forwarding for ZPA switched and the &lt;a href=&quot;https://help.zscaler.com/zpa/adding-ip-ranges&quot; target=&quot;_blank&quot;&gt;Send Location Hint to Client Connecto&lt;/a&gt;r option was enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;e723c1c9fd6018a2e8288545843ebd6d4&quot;&gt;Fixes an issue where the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-device-posture-profiles#Client-Certificate&quot; target=&quot;_blank&quot;&gt;Client Certificate&lt;/a&gt; device posture check wasn’t evaluated correctly for a partner tenant.&lt;/li&gt;&lt;li data-list-item-id=&quot;eb20d8c94f3d0578b867c2928f72bc154&quot;&gt;Fixes an issue where Zscaler Client Connector didn’t apply the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#firewall&quot; target=&quot;_blank&quot;&gt;Block All Inbound Traffic&lt;/a&gt; firewall settings correctly after a policy update.&lt;/li&gt;&lt;li data-list-item-id=&quot;e1d436eaa061aec3a17c7da5b3d6cd33f&quot;&gt;Fixes an issue with the fail-close, application bypass, block domain profile detection, and captive portal lockdown features that could cause a tunnel crash.&lt;/li&gt;&lt;li data-list-item-id=&quot;e336088c917d1f0348a86f6ea07fe004e&quot;&gt;Fixes an issue where, if the primary DNS server returned NXDOMAIN (Non-Existent Domain) and the secondary DNS server failed, Zscaler Client Connector stayed on an On-Trusted Network and didn&#039;t switch to an Off-Trusted Network.&lt;/li&gt;&lt;li data-list-item-id=&quot;ecd895803fa2e223de738bdde2c3d789d&quot;&gt;Fixes an issue where, in a no-default route environment, policy updates were sent directly instead of through the tunnel even though &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#advanced&quot; target=&quot;_blank&quot;&gt;Tunnel Internal Client Connector Traffic&lt;/a&gt; was enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;e8c57f260cbbfff0f1c7930f2279adf54&quot;&gt;Fixes an issue where Acceptable Use Policy (AUP) data was reset during ZPA reauthentication, resulting in ZPA entitlement being removed for multiple users.&lt;/li&gt;&lt;li data-list-item-id=&quot;e0550fefa377e0bf3ab61181aff942d80&quot;&gt;Fixes an issue where, for devices authenticating with an IdP as a ZPA app segment and using the machine tunnel on a network identified by Trusted Network Criteria, first-time enrollment failed during ZPA registration if the app profile had &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#Business_Continuity&quot; target=&quot;_blank&quot;&gt;business continuity&lt;/a&gt; enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;e200e9917c8613b40fc75f6b51f82d286&quot;&gt;Fixes an issue where VPN Service Edge tunnel connections intermittently failed or dropped after logging off and then logging back in to Windows.&lt;/li&gt;&lt;li data-list-item-id=&quot;e25b64ff6de08268d4ce3b8ccfbbd780e&quot;&gt;Updates the network detection process to treat network detection failures as being on an Off-Trusted Network to prevent devices from remaining in an On-Trusted Network state if DNS hostname resolution is delayed.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.9.0.412</version>
                                                <pubDate>Tue, 30 Jun 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1541468 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.6.0.457 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=Windows&amp;applicable_version=4.6.0.457&amp;deployment_date=2026-06-01&amp;id=1540969</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;e988bb9d28340f5b58c9d0b710eb94025&quot;&gt;Fixes an authentication bypass issue for Zscaler Client Connector to Zscaler Client Connector Portal-only communications. (CVE-2026-59564)&lt;/li&gt;&lt;li data-list-item-id=&quot;e4a76bae5cdd7b7eb91c468b59bfbe403&quot;&gt;Mitigates multiple remote code execution vulnerabilities. (CVE-2026-59568)&lt;/li&gt;&lt;li data-list-item-id=&quot;eaacab6a4dbe349dbf38fed504180629e&quot;&gt;Fixes multiple vulnerabilities that allowed for local privilege escalation. (CVE-2026-59567)&lt;/li&gt;&lt;li data-list-item-id=&quot;e58420c7cf7204363079d64959e31c6f0&quot;&gt;Fixes a local and kernel denial-of-service attack vector. (CVE-2026-59565)&lt;/li&gt;&lt;li data-list-item-id=&quot;e1416e9c1458b0da3e56e079c278013ec&quot;&gt;Fixes an issue where users couldn&#039;t change their Windows password while Zscaler Client Connector was connected over a machine tunnel in Strict Enforcement mode.&lt;/li&gt;&lt;li data-list-item-id=&quot;e03daeb905bc6827e577444e5f867dd26&quot;&gt;Fixes out-of-bound reads that could occur when parsing &lt;code&gt;ClientHello&lt;/code&gt; messages, which could result in the ZSATunnel crashing.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.6.0.457</version>
                                                <pubDate>Mon, 01 Jun 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1540969 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.7.0.317 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=Windows&amp;applicable_version=4.7.0.317&amp;deployment_date=2026-06-01&amp;id=1540968</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;ebea5def1dcf6170c1480810b2b065efb&quot;&gt;Fixes an authentication bypass issue for Zscaler Client Connector to Zscaler Client Connector Portal-only communications. (CVE-2026-59564)&lt;/li&gt;&lt;li data-list-item-id=&quot;ef4d0ef9f979c32156d2d28c0d09cca3e&quot;&gt;Mitigates multiple remote code execution vulnerabilities. (CVE-2026-59568)&lt;/li&gt;&lt;li data-list-item-id=&quot;eaba9ef3cae9e4ca87a9d9443584d295a&quot;&gt;Fixes multiple vulnerabilities that allowed for local privilege escalation. (CVE-2026-59567)&lt;/li&gt;&lt;li data-list-item-id=&quot;e39f56530621d09eafcc78e20333d221a&quot;&gt;Fixes a local and kernel denial-of-service attack vector. (CVE-2026-59565)&lt;/li&gt;&lt;li data-list-item-id=&quot;e36045aee91634d28567b51eab5813813&quot;&gt;Fixes an issue where, if Zscaler Client Connector is upgraded on a device with a Windows reboot pending (e.g., after a Windows update), there could be a delay in installing the Zscaler Client Connector driver which could cause the system to enter an error state (display a blue screen) after the upgrade or system restart.&lt;/li&gt;&lt;li data-list-item-id=&quot;e464e42321ac745d1e1d4554dc38ec900&quot;&gt;Fixes an issue where traffic bypassed for URLs with hostnames greater than 64 characters resulted in truncated hostnames in Zscaler Internet Access (ZIA) logs when &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#notification&quot; target=&quot;_blank&quot;&gt;Flow Logging&lt;/a&gt; was enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;e6cdc7dce231da8ccb75966ab5d9316c6&quot;&gt;Fixes an issue where users couldn&#039;t change their Windows password while Zscaler Client Connector was connected over a machine tunnel in Strict Enforcement mode.&lt;/li&gt;&lt;li data-list-item-id=&quot;e22b8005160dd9f216b3e93b169a9a902&quot;&gt;Updates the LWF driver so it can be accessed only by a local admin Windows user&lt;/li&gt;&lt;li data-list-item-id=&quot;e31f8cedd39bcb8230cbbc4ba24a03478&quot;&gt;Fixes an issue where domain profile detection failed after a Zscaler Private Access (ZPA) reauthentication timeout, leaving Windows Defender Firewall devices on the Public profile.&lt;/li&gt;&lt;li data-list-item-id=&quot;ed6d13fb1065c294ea951cf3d1f67db69&quot;&gt;Fixes an issue where incorrect handling of DNS resolution over TCP for ZPA domains caused intermittent application access failures.&lt;/li&gt;&lt;li data-list-item-id=&quot;ec4ecaf44d1da7d7e09ae628f781cbaee&quot;&gt;Fixes an issue that caused intermittent DNS timeouts and sporadic connection instability for VPN traffic bypassed using process-based application bypasses.&lt;/li&gt;&lt;li data-list-item-id=&quot;e6ddadf466b62713bd45959f22cad5a54&quot;&gt;Fixes an issue where Zscaler Client Connector failed to properly handle bursts of DNS requests, resulting in intermittent DNS failures and failures with Cisco ISE postures.&lt;/li&gt;&lt;li data-list-item-id=&quot;ea0520e57a084a1595e63f8585315a710&quot;&gt;Fixes an issue where a Windows driver change resulted in intermittent connectivity for devices with checksum offloading enabled in the network adapter settings.&lt;/li&gt;&lt;li data-list-item-id=&quot;e7b57dea0c62cef71d5f2848cbb6a9aed&quot;&gt;Fixes an issue where, even if the Restore LWF Adapter Binding feature was enabled, Zscaler Client Connector didn&#039;t attempt to rebind the adapter if the initial attempt failed.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.7.0.317</version>
                                                <pubDate>Mon, 01 Jun 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1540968 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.8.0.232 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=Windows&amp;applicable_version=4.8.0.232&amp;deployment_date=2026-06-01&amp;id=1540967</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;ee5b2f8863909b6fee4460b1ceb778e5b&quot;&gt;Fixes an authentication bypass issue for Zscaler Client Connector to Zscaler Client Connector Portal-only communications. (CVE-2026-59564)&lt;/li&gt;&lt;li data-list-item-id=&quot;eaa62b93efdf87a667b28f5f1792cc3c7&quot;&gt;Mitigates multiple remote code execution vulnerabilities. (CVE-2026-59568)&lt;/li&gt;&lt;li data-list-item-id=&quot;e31cbf92692dc67a85f4881c6efcf46fa&quot;&gt;Fixes multiple vulnerabilities that allowed for local privilege escalation. (CVE-2026-59567)&lt;/li&gt;&lt;li data-list-item-id=&quot;ee45e69ec4a43204dbc94f58c70cb33fe&quot;&gt;Fixes a local and kernel denial-of-service attack vector. (CVE-2026-59565)&lt;/li&gt;&lt;li data-list-item-id=&quot;ef7f1a554f345f53631e3fef92711c858&quot;&gt;Fixes an issue where traffic bypassed for URLs with hostnames greater than 64 characters resulted in truncated hostnames in Zscaler Internet Access (ZIA) logs when &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#notification&quot; target=&quot;_blank&quot;&gt;Flow Logging&lt;/a&gt; was enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;ef0182dbb9a09ea4bdb99bec93345ded4&quot;&gt;Fixes an issue where users couldn&#039;t change their Windows password while Zscaler Client Connector was connected over a machine tunnel in Strict Enforcement mode.&lt;/li&gt;&lt;li data-list-item-id=&quot;e67308c11897f8e1f6fac4d32409f6a4c&quot;&gt;Fixes an issue where domain profile detection failed after a Zscaler Private Access (ZPA) reauthentication timeout, leaving Windows Defender Firewall devices on the Public profile.&lt;/li&gt;&lt;li data-list-item-id=&quot;ecffdd6c75627c9d6b587343361108224&quot;&gt;Fixes an issue where Zscaler Client Connector intermittently disconnected due to repeatedly restarting the tunnel.&lt;/li&gt;&lt;li data-list-item-id=&quot;ee14b935e8401a9793aca7dab58304849&quot;&gt;Fixes an issue where incorrect handling of DNS resolution over TCP for ZPA domains caused intermittent application access failures.&lt;/li&gt;&lt;li data-list-item-id=&quot;ef10374956558f5cb59809f001ec6b17b&quot;&gt;Fixes an issue that caused intermittent DNS timeouts and sporadic connection instability for VPN traffic bypassed using process-based application bypasses.&lt;/li&gt;&lt;li data-list-item-id=&quot;e79a51a1b82dbc63eef13bdcec5b24832&quot;&gt;Fixes an issue where Zscaler Client Connector failed to properly handle bursts of DNS requests, resulting in intermittent DNS failures and failures with Cisco ISE postures.&lt;/li&gt;&lt;li data-list-item-id=&quot;effd7ba64c3d484a70dc3ea209e918548&quot;&gt;Fixes an issue where a Windows driver change resulted in intermittent connectivity for devices with checksum offloading enabled in the network adapter settings.&lt;/li&gt;&lt;li data-list-item-id=&quot;e67df48248c029535f08740fc2cd8a013&quot;&gt;Fixes an issue where captive portal detection failed on networks using captive portals that return chunked HTTP responses (uncommon on guest Wi-Fi).&lt;/li&gt;&lt;li data-list-item-id=&quot;eb75ea6b55939cab2b19758ab6cbc9b7a&quot;&gt;Fixes an issue where captive portal detection failed when a device connected to a captive portal that redirected Zscaler Client Connector to an HTTPS site on a non-standard port or to a site with an atypical URL path (e.g., no leading slash).&lt;/li&gt;&lt;li data-list-item-id=&quot;eb4eacde71b7066c47685eab100e7e16b&quot;&gt;Fixes an issue where IP inclusions weren’t enforced after a device resumed from a multi-day sleep, resulting in internet traffic bypassing Zscaler Internet Access (ZIA) after switching network types.&lt;/li&gt;&lt;li data-list-item-id=&quot;e56d0c5e96a1ba1fc53e7a24f311dd0e4&quot;&gt;Fixes an issue where, even if the Restore LWF Adapter Binding feature was enabled, Zscaler Client Connector didn&#039;t attempt to rebind the adapter if the initial attempt failed.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.8.0.232</version>
                                                <pubDate>Mon, 01 Jun 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1540967 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.9.0.372 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=Windows&amp;applicable_version=4.9.0.372&amp;deployment_date=2026-06-01&amp;id=1540954</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;ec93f11e6295fb3db7e3b660ffd388d7f&quot;&gt;Fixes an authentication bypass issue for Zscaler Client Connector to Zscaler Client Connector Portal-only communications. (CVE-2026-59564)&lt;/li&gt;&lt;li data-list-item-id=&quot;e098ba981ae6d95916f52f2b03103c6ba&quot;&gt;Mitigates multiple remote code execution vulnerabilities. (CVE-2026-59568)&lt;/li&gt;&lt;li data-list-item-id=&quot;e844054b45bba00285af09e88e92d8d72&quot;&gt;Fixes multiple vulnerabilities that allowed for local privilege escalation. (CVE-2026-59567)&lt;/li&gt;&lt;li data-list-item-id=&quot;e481fc93c5fbf580336ee41ed6d5fb2b5&quot;&gt;Fixes a local and kernel denial-of-service attack vector. (CVE-2026-59565)&lt;/li&gt;&lt;li data-list-item-id=&quot;eca8b4ff615af53f8245914345fd11468&quot;&gt;Fixes an issue where, if Zscaler Client Connector is upgraded on a device with a Windows reboot pending (e.g., after a Windows update), there could be a delay in installing the Zscaler Client Connector driver which could cause the system to enter an error state (display a blue screen) after the upgrade or system restart.&lt;/li&gt;&lt;li data-list-item-id=&quot;edbfff3ecb34bcefb2e59fd7abf0d850a&quot;&gt;Fixes an issue where traffic bypassed for URLs with hostnames greater than 64 characters resulted in truncated hostnames in Zscaler Internet Access (ZIA) logs when &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#notification&quot; target=&quot;_blank&quot;&gt;Flow Logging&lt;/a&gt; was enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;e5403028313030aa5186080626118052a&quot;&gt;Fixes an issue where users couldn&#039;t change their Windows password while Zscaler Client Connector was connected over a machine tunnel in Strict Enforcement mode.&lt;/li&gt;&lt;li data-list-item-id=&quot;ee4106b2f8e2c2e785572962bbf6378ad&quot;&gt;Fixes an issue where domain profile detection failed after a Zscaler Private Access (ZPA) reauthentication timeout, leaving Windows Defender Firewall devices on the Public profile.&lt;/li&gt;&lt;li data-list-item-id=&quot;ec82c41b7de9a1163585e40a4c42147bd&quot;&gt;Fixes an issue where Zscaler Client Connector intermittently disconnected due to repeatedly restarting the tunnel.&lt;/li&gt;&lt;li data-list-item-id=&quot;ede5cc28ded2a83939ad0f10ea7d34dca&quot;&gt;Fixes an issue where incorrect handling of DNS resolution over TCP for ZPA domains caused intermittent application access failures.&lt;/li&gt;&lt;li data-list-item-id=&quot;e5d35ec72989ba82f7cfef8c01b1816ed&quot;&gt;Fixes an issue that caused intermittent DNS timeouts and sporadic connection instability for VPN traffic bypassed using process-based application bypasses.&lt;/li&gt;&lt;li data-list-item-id=&quot;eef6953d0755c18f31d09bf1f74494327&quot;&gt;Fixes an issue where Zscaler Client Connector failed to properly handle bursts of DNS requests, resulting in intermittent DNS failures and failures with Cisco ISE postures.&lt;/li&gt;&lt;li data-list-item-id=&quot;e5e0661bbc79a0bba6231e445ac0e6658&quot;&gt;Fixes an issue where captive portal detection failed on networks using captive portals that return chunked HTTP responses (uncommon on guest Wi-Fi).&lt;/li&gt;&lt;li data-list-item-id=&quot;e1530abd11dc7d7d5d3cf768787e4555f&quot;&gt;Fixes an issue where captive portal detection failed when a device connected to a captive portal that redirected Zscaler Client Connector to an HTTPS site on a non-standard port or to a site with an atypical URL path (e.g., no leading slash).&lt;/li&gt;&lt;li data-list-item-id=&quot;eb4143945f23758b67a2bb9ab85256281&quot;&gt;Fixes an issue where IP inclusions weren’t enforced after a device resumed from a multi-day sleep, resulting in internet traffic bypassing ZIA after switching network types.&lt;/li&gt;&lt;li data-list-item-id=&quot;e1020b85846ebf78c8d4c960d9018cdd0&quot;&gt;Fixes an issue where, even if the Restore LWF Adapter Binding feature was enabled, Zscaler Client Connector didn&#039;t attempt to rebind the adapter if the initial attempt failed.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release in Limited Availability</category>
                                    <version>4.9.0.372</version>
                                                <pubDate>Mon, 01 Jun 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1540954 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.8.0.190 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=Windows&amp;applicable_version=4.8.0.190&amp;deployment_date=2026-05-13&amp;id=1540728</link>
                <description>&lt;p&gt;Fixes an issue where, if Zscaler Client Connector is upgraded on a device with a Windows reboot pending (e.g., after a Windows update), there could be a delay in installing the Zscaler Client Connector driver which could cause the system to enter an error state (display a blue screen) after the upgrade or system restart.&lt;/p&gt;</description>
                <category>Release Available</category>
                                    <version>4.8.0.190</version>
                                                <pubDate>Wed, 13 May 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1540728 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.7.0.248 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=Windows&amp;applicable_version=4.7.0.248&amp;deployment_date=2026-05-01&amp;id=1539759</link>
                <description>&lt;p class=&quot;note&quot;&gt;This version of Zscaler Client Connector has a known issue affecting the Zscaler Client Connector filter driver. In certain scenarios, the issue could cause the system to enter an error state (display a blue screen) during a Zscaler Client Connector upgrade or system startup. If you encounter this issue, contact Zscaler Support for assistance. The issue has been corrected on Zscaler Client Connector version 4.7.0.317.&lt;/p&gt;&lt;ul&gt;&lt;li data-list-item-id=&quot;e1017fa3d4bda9a61898185b4bb51c34c&quot;&gt;Fixes an intermittent issue where the LTE cellular adapter was disconnected after a driver upgrade during a Zscaler Client Connector upgrade and didn&#039;t reconnect until the user reset the adapter.&lt;/li&gt;&lt;li data-list-item-id=&quot;ec91a0b9c9bee08185bc61a5ef02780a7&quot;&gt;Fixes an issue where Zscaler Private Access (ZPA) remained in an &lt;code&gt;Authentication Required&lt;/code&gt; state after clicking Authenticate for a partner tenant when the tenant&#039;s ZPA re-registration was pending.&lt;/li&gt;&lt;li data-list-item-id=&quot;e7b748fb3e2b448d46ca52e803693866d&quot;&gt;Fixes an issue where users received a &lt;code&gt;Private Access is Connected&lt;/code&gt; notification in the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/viewing-notifications-zscaler-client-connector#win-notification&quot; target=&quot;_blank&quot;&gt;Notifications window&lt;/a&gt; in the app in addition to the &lt;code&gt;Private Access is Connected (Business Continuity mode)&lt;/code&gt; notification when in business continuity.&lt;/li&gt;&lt;li data-list-item-id=&quot;e863fbfa7811acfa0dc15dc3eed704945&quot;&gt;Fixes an issue where the &lt;a href=&quot;https://help.zscaler.com/deception/deploying-endpoint-deception-zscaler-client-connector-windows#endpoint-deception-verify-zd-service-status-client-connector&quot; target=&quot;_blank&quot;&gt;Deception service didn&#039;t restart&lt;/a&gt; immediately after users logged out of and then logged back in to Zscaler Client Connector.&lt;/li&gt;&lt;li data-list-item-id=&quot;e8c3f45c83ca1044db27e08f4bb56fbbc&quot;&gt;Fixes an issue where users received an invalid password error after entering the correct Exit Password if they logged out of Zscaler Client Connector before trying to exit the app.&lt;/li&gt;&lt;li data-list-item-id=&quot;e1369e51edcda8d72aea68c1550d00c30&quot;&gt;Fixes an issue where users could experience a blue screen after uninstalling the Eggplant Functional application when anti-tampering was enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;e13c109dd20317b66fc78559dd0be7564&quot;&gt;Fixes an issue where Endpoint Data Loss Prevention (DLP) wasn&#039;t enabled after starting the Zscaler Client Connector app if a previous attempt to uninstall Zscaler Client Connector didn&#039;t finish correctly.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.7.0.248</version>
                                                <pubDate>Fri, 01 May 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1539759 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.8.0.172 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=Windows&amp;applicable_version=4.8.0.172&amp;deployment_date=2026-05-01&amp;id=1539782</link>
                <description>&lt;p class=&quot;note&quot;&gt;This version of Zscaler Client Connector has a known issue affecting the Zscaler Client Connector filter driver. In certain scenarios, the issue could cause the system to enter an error state (display a blue screen) during a Zscaler Client Connector upgrade or system startup. If you encounter this issue, contact Zscaler Support for assistance. The issue has been corrected on Zscaler Client Connector version 4.8.0.190.&lt;/p&gt;&lt;ul&gt;&lt;li data-list-item-id=&quot;e39abca9ab076b1ec0e4b919fed1aa2e6&quot;&gt;Fixes an intermittent issue where the LTE cellular adapter was disconnected after a driver upgrade during a Zscaler Client Connector upgrade and didn&#039;t reconnect until the user reset the adapter.&lt;/li&gt;&lt;li data-list-item-id=&quot;e60c95c1d14f4268733d41f4d3256f655&quot;&gt;Fixes an issue where Zscaler Private Access (ZPA) remained in an &lt;code&gt;Authentication Required&lt;/code&gt; state after clicking Authenticate for a partner tenant when the tenant&#039;s ZPA re-registration was pending.&lt;/li&gt;&lt;li data-list-item-id=&quot;ee559cc71b3e1d4bf702734c70cca458f&quot;&gt;Fixes an issue where users received a &lt;code&gt;Private Access is Connected&lt;/code&gt; notification in the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/viewing-notifications-zscaler-client-connector#win-notification&quot; target=&quot;_blank&quot;&gt;Notifications window&lt;/a&gt; in the app in addition to the &lt;code&gt;Private Access is Connected (Business Continuity mode)&lt;/code&gt; notification when in business continuity.&lt;/li&gt;&lt;li data-list-item-id=&quot;ee27b0a3b39eb91b74c48f4ca0a0a77b6&quot;&gt;Fixes an issue where, for users with an app profile with a &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#general&quot; target=&quot;_blank&quot;&gt;notification template&lt;/a&gt; selected, the Show All Notifications and Show Private Access Reauthentication Notification settings on the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/viewing-notifications-zscaler-client-connector&quot; target=&quot;_blank&quot;&gt;More window&lt;/a&gt; in the app weren&#039;t reset to the default values from the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-notification-templates-zscaler-client-connector&quot; target=&quot;_blank&quot;&gt;notification template&lt;/a&gt; after upgrading.&lt;/li&gt;&lt;li data-list-item-id=&quot;ea6f47f44dff2faa3c68f27fdcb59132f&quot;&gt;Fixes an issue where &lt;a href=&quot;https://help.zscaler.com/zia/configuring-euns-inline-web-dlp&quot; target=&quot;_blank&quot;&gt;Inline Web DLP&lt;/a&gt; and &lt;a href=&quot;https://help.zscaler.com/zia/configuring-euns-endpoint-dlp&quot; target=&quot;_blank&quot;&gt;Endpoint DLP&lt;/a&gt; notifications weren&#039;t defined as critical, resulting in both notifications being suppressed for users with the Show notification pop-ups option disabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;e547ea2e5772bde37baf409a2c569c963&quot;&gt;Fixes an issue where the &lt;a href=&quot;https://help.zscaler.com/deception/deploying-endpoint-deception-zscaler-client-connector-windows#endpoint-deception-verify-zd-service-status-client-connector&quot; target=&quot;_blank&quot;&gt;Deception service didn&#039;t restart&lt;/a&gt; immediately after users logged out of and then logged back in to Zscaler Client Connector.&lt;/li&gt;&lt;li data-list-item-id=&quot;e342f8624adaca3f1305ae1cc5c8e3ba3&quot;&gt;Fixes an issue where the original system proxy settings were not restored due to a crash when &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#pac-proxy&quot; target=&quot;_blank&quot;&gt;Cache System Proxy on Startup&lt;/a&gt; was enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;ec783774eeeee799cba56a847de8931e6&quot;&gt;Fixes an issue where users could experience a blue screen after uninstalling the Eggplant Functional application when anti-tampering was enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;ea826467d7ab24cdc22c6f76aa00fc8f5&quot;&gt;Fixes an issue where Endpoint Data Loss Prevention (DLP) wasn&#039;t enabled after starting the Zscaler Client Connector app if a previous attempt to uninstall Zscaler Client Connector didn&#039;t finish correctly.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.8.0.172</version>
                                                <pubDate>Fri, 01 May 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1539782 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.9.0.331 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=Windows&amp;applicable_version=4.9.0.331&amp;deployment_date=2026-04-30&amp;id=1540081</link>
                <description>&lt;p&gt;Fixes an issue where Zscaler Client Connector didn&#039;t fail over to the &lt;a href=&quot;https://help.zscaler.com/zpa/configuring-network-segments&quot; target=&quot;_blank&quot;&gt;secondary DNS server on the network segment&lt;/a&gt; if the device&#039;s network adapter had only one DNS server configured and the primary DNS server was unresponsive.&lt;/p&gt;</description>
                <category>Release in Limited Availability</category>
                                    <version>4.9.0.331</version>
                                                <pubDate>Thu, 30 Apr 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1540081 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.6.0.418 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=Windows&amp;applicable_version=4.6.0.418&amp;deployment_date=2026-04-29&amp;id=1540116</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;efd45b81cce0984674d7e1d4f2a9cce9f&quot;&gt;Fixes an issue where the &lt;a href=&quot;https://help.zscaler.com/deception/deploying-endpoint-deception-zscaler-client-connector-windows#endpoint-deception-verify-zd-service-status-client-connector&quot; target=&quot;_blank&quot;&gt;Deception service didn&#039;t restart&lt;/a&gt; immediately after users logged out of and then logged back in to Zscaler Client Connector.&lt;/li&gt;&lt;li data-list-item-id=&quot;e1f32632d5d356e62d978972e0b8aabd0&quot;&gt;Fixes an issue where users received an invalid password error after entering the correct Exit Password if they logged out of Zscaler Client Connector before trying to exit the app.&lt;/li&gt;&lt;li data-list-item-id=&quot;eaab39f50c30d05fa10602eefc9daca72&quot;&gt;Fixes an issue where users could experience a blue screen after uninstalling the Eggplant Functional application when anti-tampering was enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;e549e88dd2b1769524835fb48efc57349&quot;&gt;Fixes an issue where Endpoint Data Loss Prevention (DLP) wasn&#039;t enabled after starting the Zscaler Client Connector app if a previous attempt to uninstall Zscaler Client Connector didn&#039;t finish correctly.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.6.0.418</version>
                                                <pubDate>Wed, 29 Apr 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1540116 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.9.0.330 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=Windows&amp;applicable_version=4.9.0.330&amp;deployment_date=2026-04-21&amp;id=1539860</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;e184054000c2e86d442a32dcb15782e85&quot;&gt;Fixes an issue where the original system proxy settings were not restored due to a crash when &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#pac-proxy&quot; target=&quot;_blank&quot;&gt;Cache System Proxy on Startup&lt;/a&gt; was enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;e5304b818c8ab01f4c8b7eb6d9dcfa1e7&quot;&gt;Fixes an issue where, for users with an app profile with a &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#general&quot; target=&quot;_blank&quot;&gt;notification template&lt;/a&gt; selected, the Show All Notifications and Show Private Access Reauthentication Notification settings on the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/viewing-notifications-zscaler-client-connector&quot; target=&quot;_blank&quot;&gt;More window&lt;/a&gt; in the app weren&#039;t reset to the default values from the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-notification-templates-zscaler-client-connector&quot; target=&quot;_blank&quot;&gt;notification template&lt;/a&gt; after upgrading.&lt;/li&gt;&lt;li data-list-item-id=&quot;e17273147437b7e125b8455a8d28ef0dc&quot;&gt;Fixes an issue where users could experience a blue screen after uninstalling the Eggplant Functional application when anti-tampering was enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;e6916ea240e90fc9a0e300112ad4af8a7&quot;&gt;Fixes an issue where &lt;a href=&quot;https://help.zscaler.com/zia/configuring-euns-inline-web-dlp&quot; target=&quot;_blank&quot;&gt;Inline Web DLP&lt;/a&gt; and &lt;a href=&quot;https://help.zscaler.com/zia/configuring-euns-endpoint-dlp&quot; target=&quot;_blank&quot;&gt;Endpoint DLP&lt;/a&gt; notifications weren&#039;t defined as critical, resulting in both notifications being suppressed for users with the Show notification pop-ups option disabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;e2fc0a5935dcb6ad9e7e05424370cb9c1&quot;&gt;Fixes an issue where Endpoint Data Loss Prevention (DLP) wasn&#039;t enabled after starting the Zscaler Client Connector app if a previous attempt to uninstall Zscaler Client Connector didn&#039;t finish correctly.&lt;/li&gt;&lt;li data-list-item-id=&quot;e7a5b3d514920f6d5610eb2f066a2517f&quot;&gt;Fixes an issue where a Windows driver change resulted in intermittent connectivity for devices with checksum offloading enabled in the network adapter settings.&lt;/li&gt;&lt;li data-list-item-id=&quot;ebe425096ab84d713f89a8f6538b844ed&quot;&gt;Fixes an LWF driver issue that could cause performance degradation when downloading over Zscaler Tunnel (Z-Tunnel) 2.0.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release in Limited Availability</category>
                                    <version>4.9.0.330</version>
                                                <pubDate>Tue, 21 Apr 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1539860 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.7.0.239 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=Windows&amp;applicable_version=4.7.0.239&amp;deployment_date=2026-04-07&amp;id=1539500</link>
                <description>&lt;p class=&quot;note&quot;&gt;This version of Zscaler Client Connector has a known issue affecting the Zscaler Client Connector filter driver. In certain scenarios, the issue could cause the system to enter an error state (display a blue screen) during a Zscaler Client Connector upgrade or system startup. If you encounter this issue, contact Zscaler Support for assistance. The issue has been corrected on Zscaler Client Connector version 4.7.0.317.&lt;/p&gt;&lt;p&gt;Fixes performance issues that occurred when accessing virtual machines if Hyper-V was enabled on the device.&lt;/p&gt;</description>
                <category>Release Available</category>
                                    <version>4.7.0.239</version>
                                                <pubDate>Tue, 07 Apr 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1539500 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.6.0.410 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=Windows&amp;applicable_version=4.6.0.410&amp;deployment_date=2026-03-31&amp;id=1539501</link>
                <description>&lt;ul&gt;&lt;li&gt;Fixes performance issues that occurred when accessing virtual machines if Hyper-V was enabled on the device.&lt;/li&gt;&lt;li&gt;Fixes performance issues that occurred after enabling a Hyper-V external switch with a Wi-Fi adapter.&lt;/li&gt;&lt;li&gt;Fixes out-of-bound reads that could occur when parsing ClientHello messages, which could result in the ZSATunnel crashing.&lt;/li&gt;&lt;li&gt;Fixes a driver issue that could cause process-based bypasses, the Block Domain Profile Detection feature, the captive portal lockdown feature, and fail-close settings to work incorrectly.&lt;/li&gt;&lt;li&gt;Fixes a tunnel IP handling issue that caused the VPN (for Legacy Apps) feature to not work, resulting in a blank VPN Tunnel section on the Private Access window in the app.&lt;/li&gt;&lt;li&gt;Fixes an issue where Zscaler Client Connector didn&#039;t refresh the driver state after the device woke from sleep, causing the app to display a &lt;code&gt;Driver Error&lt;/code&gt; even though it was connected to the Zscaler service.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.6.0.410</version>
                                                <pubDate>Tue, 31 Mar 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1539501 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.8.0.156 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=Windows&amp;applicable_version=4.8.0.156&amp;deployment_date=2026-03-31&amp;id=1539499</link>
                <description>&lt;p class=&quot;note&quot;&gt;This version of Zscaler Client Connector has a known issue affecting the Zscaler Client Connector filter driver. In certain scenarios, the issue could cause the system to enter an error state (display a blue screen) during a Zscaler Client Connector upgrade or system startup. If you encounter this issue, contact Zscaler Support for assistance. The issue has been corrected on Zscaler Client Connector version 4.8.0.190.&lt;/p&gt;&lt;ul&gt;&lt;li data-list-item-id=&quot;ecc4386f6aa266f6d5200ed0ef902af1c&quot;&gt;Fixes performance issues that occurred when accessing virtual machines if Hyper-V was enabled on the device.&lt;/li&gt;&lt;li data-list-item-id=&quot;e167f8495e3d0fb231697c1fcb9d5fe47&quot;&gt;Fixes an issue where VPN Gateway Bypasses weren&#039;t updated after switching from the machine tunnel to the user tunnel.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.8.0.156</version>
                                                <pubDate>Tue, 31 Mar 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1539499 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.9 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=Windows&amp;applicable_version=4.9&amp;deployment_date=2026-03-31&amp;id=1539042</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;e7cf8eb9a541d0aa0583b0f393d4f8b9e&quot;&gt;Adds support for Zscaler Deception service entitlement for Authentication Service tenants.&lt;/li&gt;&lt;li data-list-item-id=&quot;e3a3d0be02372a46f8c6eee3603ddecae&quot;&gt;Supports sending the network type for the Network Share, Printing, and Device Control channels when creating policy rules for Endpoint Data Loss Prevention (DLP). To learn more, see &lt;a href=&quot;https://help.zscaler.com/zia/configuring-endpoint-dlp-policy-rules&quot; target=&quot;_blank&quot;&gt;Configuring Endpoint DLP Policy Rules&lt;/a&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;e781eb7ece31b3eede868287b5d1890bc&quot;&gt;Supports tunneling Azure Private Link domains over Zscaler Private Access (ZPA) by extracting the CNAME records from the DNS response and matching it against Zscaler Private Access (ZPA) applications. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zpa/configuring-private-link-domains&quot; target=&quot;_blank&quot;&gt;Configuring Private Link Domains&lt;/a&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;e580367e8efc2f1b650fa4201544a7c5b&quot;&gt;&lt;p&gt;Supports always using the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#pac-proxy&quot; target=&quot;_blank&quot;&gt;V8 JavaScript based PAC Parser&lt;/a&gt; regardless of the setting in a user’s app profile. This change is in support of &lt;a href=&quot;https://help.zscaler.com/eos-eol/end-support-spidermonkey-based-pac-parser&quot; target=&quot;_blank&quot;&gt;deprecating the Legacy (SpiderMonkey-based) PAC parser&lt;/a&gt;.&lt;/p&gt;&lt;p class=&quot;note&quot;&gt;If your organization has multiple versions of Zscaler Client Connector installed across devices, devices with versions 4.8 and earlier installed continue to use the PAC parser selected in the app profile.&lt;/p&gt;&lt;/li&gt;&lt;li data-list-item-id=&quot;eddd972f612a189d1235e37686dd88275&quot;&gt;Supports using a secondary DNS server as a backup in network segments configured for VPN (for Legacy Apps). To learn more, see &lt;a href=&quot;https://help.zscaler.com/zpa/configuring-network-segments&quot; target=&quot;_blank&quot;&gt;Configuring Network Segments&lt;/a&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;ef8d45d86e2970a3af3bca699c99c3e73&quot;&gt;Supports immediate ZPA reauthentication after ZPA authentication expires due to an action selected in the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#auth&quot; target=&quot;_blank&quot;&gt;Force ZPA authentication to expire&lt;/a&gt; option instead of waiting for the user’s next ZPA access attempt. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#auth&quot; target=&quot;_blank&quot;&gt;Configuring Zscaler Client Connector App Profiles&lt;/a&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;e5d6e1651e29606f8d3d8ec784a80e200&quot;&gt;Supports delaying pop-up notifications for device posture failures after the user tunnel is established. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-notification-templates-zscaler-client-connector&quot; target=&quot;_blank&quot;&gt;Configuring Notification Templates for Zscaler Client Connector&lt;/a&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;e2a29ac744dff8ea067b904b0fef83705&quot;&gt;Supports selecting whether to send the UPN (User Principal Name) or the SAM (Security Account Manager) account name in the &lt;code&gt;login_hint&lt;/code&gt; parameter used to automatically populate the username. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-automatic-username-population-idp-authentication&quot; target=&quot;_blank&quot;&gt;Configuring Automatic Username Population for IdP Authentication&lt;/a&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;e3ae9bf4083acebe4ae8e67be973f697a&quot;&gt;Adds the ability to update some installation parameters using the CLI without having to reinstall Zscaler Client Connector. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/interacting-zscaler-client-connector-remotely&quot; target=&quot;_blank&quot;&gt;Interacting with Zscaler Client Connector Remotely&lt;/a&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;e356e945e8fbe0ea9d0cda16d710a5ecb&quot;&gt;Streamlines the end user experience of pop-up notifications by adding system tray options to pause notifications, rewording existing notifications for clarity, and removing unnecessary notifications. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/using-zscaler-client-connector&quot; target=&quot;_blank&quot;&gt;Using Zscaler Client Connector.&lt;/a&gt;&lt;/li&gt;&lt;li data-list-item-id=&quot;ea2a2a560660597d499dc42a41b590c42&quot;&gt;Supports blocking all traffic and allowing only PAC file exclusions when in strict enforcement mode. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#pac-proxy&quot; target=&quot;_blank&quot;&gt;Configuring Zscaler Client Connector App Profiles&lt;/a&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;ed60c73e9321ca565bd9d27dd520d8664&quot;&gt;Supports checking for specific software versions for the following device postures: Process Check, Detect Carbon Black, Detect CrowdStrike, Detect SentinelOne, and Detect Microsoft Defender. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-device-posture-profiles&quot; target=&quot;_blank&quot;&gt;Configuring Device Posture Profiles&lt;/a&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;ee965cc5502a3aece3a8a7a5bcb30ce84&quot;&gt;Supports controlling how Zscaler Client Connector interacts with hardware offloading on network adapters to resolve compatibility issues. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#adv&quot; target=&quot;_blank&quot;&gt;Configuring Zscaler Client Connector App Profiles&lt;/a&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;e3342f8e5ffb40fcda379a23aec991e9f&quot;&gt;Supports customizing the company logos and company name that displays on the app and in pop-up notifications. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/customizing-zscaler-client-connector-theme&quot; target=&quot;_blank&quot;&gt;Customizing the Zscaler Client Connector Theme&lt;/a&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;e74d99b39204d6ada2c1bebda24a205af&quot;&gt;Fixes an issue where traffic was intermittently sent to the secondary Public Service Edge instead of the primary Public Service Edge after the device woke from sleep.&lt;/li&gt;&lt;li data-list-item-id=&quot;ebd2688ed018cd41272c5f50b26370653&quot;&gt;Fixes an issue where the Block Domain Profile Detection feature didn&#039;t correctly block domain profile detection when switching to a network type with the feature enabled if the policy also had process-based bypasses enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;e50001393421540cf1c9377da4e2bea38&quot;&gt;Fixes an issue where the fail-close lockdown settings didn&#039;t apply along with captive portal lockdown if the policy also had process-based bypasses enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;ef7acfa338619640a33e1c172c1137ec0&quot;&gt;Improves the retrial logic of the VPN (for Legacy Apps) client in cases where the VPN gateway port is unreachable.&lt;/li&gt;&lt;li data-list-item-id=&quot;e34223f8906bad0677455ee47de40973e&quot;&gt;Fixes an issue when using an SCCM virtual adapter where DNS responses could be delayed after switching networks if the &lt;a href=&quot;https://help.zscaler.com/zpa/adding-ip-ranges&quot; target=&quot;_blank&quot;&gt;Send Location Hint to Client Connector&lt;/a&gt; option was enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;e0b257d6d7b73b6e1364bb229c060eb0c&quot;&gt;Fixes an issue where Zscaler Client Connector continued to use DNS suffixes from ZPA even after switching to a network type with a forwarding mode of None.&lt;/li&gt;&lt;li data-list-item-id=&quot;e4b986712e6f3fe8a2f57bf50a10542f0&quot;&gt;Fixes an issue where Zscaler Client Connector incorrectly allowed fail-close settings on the app profile to control network lockdown even if the Install WFP Driver option was disabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;e8d2745500ef001fe43a074e7dd348cf6&quot;&gt;Updates Zscaler Client Connector to monitor changes to the system-level proxy configuration and to enforce the Zscaler proxy settings based on the forwarding profile.&lt;/li&gt;&lt;li data-list-item-id=&quot;e2c92517911806ae00a53f0f5a3848801&quot;&gt;Fixes an issue where an &lt;code&gt;Internal Error&lt;/code&gt; message displayed after users clicked Verify Now in the Zscaler Client Connector app for step-up authentication for customers using the ZPA service and not the Zscaler Internet Access (ZIA) service.&lt;/li&gt;&lt;li data-list-item-id=&quot;eb66cb0369b01283d572f6109c6c16bc5&quot;&gt;Fixes an issue where, even if the device posture for posture-based service entitlement passed, ZIA was not enabled after enrollment if the user&#039;s app profile had Business Continuity enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;eacef50821e987688da89980267ae40e9&quot;&gt;Adds support for using registry keys with the REG_BINARY type with the Registry Key device posture profile.&lt;/li&gt;&lt;li data-list-item-id=&quot;e09b95e8e8a7cba35c95363e8f8b9b6e6&quot;&gt;Fixes an issue where Zscaler Client Connector couldn&#039;t retrieve the PAC file when the source was the HKEY_CURRENT_USER Registry location provided in the forwarding profile.&lt;/li&gt;&lt;li data-list-item-id=&quot;e774ce1648a9c8bb7e7e3a6b0a2638a4f&quot;&gt;Fixes an issue where Zscaler Client Connector bypassed non-DNS requests on port 53.&lt;/li&gt;&lt;li data-list-item-id=&quot;e33551a15548e68a9574209aa2470960b&quot;&gt;Fixes an issue where trusted network detection using the hostname and IP address criteria could cause a delay in switching between networks when using Zscaler Tunnel (Z-Tunnel) 2.0.&lt;/li&gt;&lt;li data-list-item-id=&quot;eefe9476d5e08e69582f3b2d139fb4085&quot;&gt;Fixes an issue where the app didn&#039;t display a device posture failure notification from ZPA if the Enable ZIA Notifications option was disabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;ea51695a516cd649eeb3debe2dd1e0967&quot;&gt;Fixes a tunnel crash that occurred after upgrading which resulted in Zscaler Client Connector remaining in a Connecting state.&lt;/li&gt;&lt;li data-list-item-id=&quot;eb2ff15db8f3e45c8387313046886ecc6&quot;&gt;Fixes an issue where DNS requests for domains added in the Domain Inclusions field in App Profiles were bypassed instead of being routed through Z-Tunnel 2.0 on IPv4-only (non-dual stack) networks.&lt;/li&gt;&lt;li data-list-item-id=&quot;e14f20118bfa8cde3bd016c9ee5bcec3e&quot;&gt;Fixes a timing issue that caused a delay in Zscaler Client Connector bypassing a URL after it was added to the app profile PAC file.&lt;/li&gt;&lt;li data-list-item-id=&quot;e2277951a9b6311b4bd8cfce367ca9e85&quot;&gt;Fixes an issue where Zscaler Client Connector didn’t bypass process-based applications with an environment variable (e.g., &lt;code&gt;%LocalAppData%&lt;/code&gt;) in the application path.&lt;/li&gt;&lt;li data-list-item-id=&quot;e0866936f9a977a8154cc45e0b5591152&quot;&gt;Fixes a timing issue where the custom app profile PAC file was not processed in time at startup, causing traffic to be forced through the default gateway domain without applying relevant bypasses and rules of the PAC file.&lt;/li&gt;&lt;li data-list-item-id=&quot;ef243aed597369e35bd7eefea5ae0b160&quot;&gt;Mitigates a vulnerability where specific session timeout conditions allowed for the bypass of application exit protections. (CVSS v3.1 Base Score: 3.2 - Low)&lt;/li&gt;&lt;li data-list-item-id=&quot;ec28fa715ce14b702af133f5589aaf7bf&quot;&gt;Fixes an issue where traffic to a domain bypassed in the PAC file could be sent to the Zscaler service when an internal Health Check port was reused by another application.&lt;/li&gt;&lt;li data-list-item-id=&quot;ebaddadb5560c406688fe627d0825a86f&quot;&gt;Fixes an issue where, if the forwarding profile was set to bypass DNS traffic on a trusted network and send the traffic to ZPA on an off-trusted network, network detection caused Zscaler Client Connector to send some DNS traffic to ZPA while on a trusted network.&lt;/li&gt;&lt;li data-list-item-id=&quot;ec7eb0a131b39dfdae5d84cb6015780a4&quot;&gt;Fixes an issue where, if automatic reauthentication failed, users received a timeout error when manually reauthenticating.&lt;/li&gt;&lt;li data-list-item-id=&quot;eb36a53589ad5e3feb94bcc06105fe2f1&quot;&gt;Fixes an issue where devices with the Domain Joined posture profile always passed the posture check, even if the domain name didn&#039;t match or the device wasn&#039;t domain joined.&lt;/li&gt;&lt;li data-list-item-id=&quot;ef25bb9282c2ee658e2c4761479497006&quot;&gt;Fixes an issue that caused an &lt;code&gt;Internal Error&lt;/code&gt; message on the Data Protection window in the app for customers using Endpoint Data Loss Prevention (DLP).&lt;/li&gt;&lt;li data-list-item-id=&quot;ea449972af0f337a06c6bee0422abb00f&quot;&gt;Updates the anti-tampering installation files to add protection to Endpoint Data Loss Prevention (DLP) internal files.&lt;/li&gt;&lt;li data-list-item-id=&quot;ea34582d449fb0306212545a8cc762525&quot;&gt;Fixes an issue where a trusted network defined by the Hostname and IP condition wasn&#039;t detected because the Zscaler Client Connector response included both the &lt;code&gt;CName&lt;/code&gt; and the &lt;code&gt;ipaddress&lt;/code&gt; in the response.&lt;/li&gt;&lt;li data-list-item-id=&quot;e27d1f0bba0bc84fca383f356380898b1&quot;&gt;Fixes an issue where the Zscaler proxy wasn&#039;t enforced in accordance with the forwarding profile when the profile was set to Enforce Proxy.&lt;/li&gt;&lt;li data-list-item-id=&quot;eb720a9b2cefe99868b4a8ec11819aebb&quot;&gt;Fixes an issue where the policy download might not occur immediately after upgrading Zscaler Client Connector, resulting in the app displaying in French if the system language was set to French but the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#UI-language-settings&quot; target=&quot;_blank&quot;&gt;Client Connector UI Language Settings&lt;/a&gt; was set to English.&lt;/li&gt;&lt;li data-list-item-id=&quot;e9bdf3e164983e94937c8fb8d1f4d1418&quot;&gt;Fixes an issue that could cause FW/AV errors on Windows 11 due to an accumulation of App Container loopback exemptions when the Disable Loopback Restriction option was enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;e16116ac7e934ef54c856a698e3be16f5&quot;&gt;Fixes an issue where confirmation messages from DLP were delayed or not displayed.&lt;/li&gt;&lt;li data-list-item-id=&quot;e5d2f2ba1907b1a67cf2cce467e568d55&quot;&gt;Fixes a DNS routing issue that caused connectivity problems for applications accessed over VPN (for Legacy Apps) on a trusted network when the DNS server was defined as an app segment.&lt;/li&gt;&lt;li data-list-item-id=&quot;e55394fd717338bf589dddff96ad6260a&quot;&gt;Fixes an issue where Zscaler Client Connector could bypass traffic on ports 53 and 67.&lt;/li&gt;&lt;li data-list-item-id=&quot;e134b31e4f2680789872da663a5b47d5c&quot;&gt;Fixes an issue where the &lt;code&gt;Reauthenticate before your access expires&lt;/code&gt; notification displayed for users on an On-Trusted Network with ZPA disabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;e9482d8efea2be6717ad9101a494f59ba&quot;&gt;Fixes out-of-bound reads that could occur when parsing ClientHello messages, which could result in the ZSATunnel crashing.&lt;/li&gt;&lt;li data-list-item-id=&quot;e01272300b4ade042d8db26d5f0fd4930&quot;&gt;Fixes inconsistent behavior where, when reconnecting to a ZPA application through an app segment with the Double Encryption option enabled, Zscaler Client Connector closed the app client connection immediately instead of holding the connections as it does when the option is disabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;e008fb78d44bedc582a22e6c4d116ec8a&quot;&gt;Mitigates a vulnerability where specific path validation conditions allowed for elevated write privileges. (CVSS v3.1 Base Score: 6.1 - Medium)&lt;/li&gt;&lt;li data-list-item-id=&quot;e970955e7481569bfe1164e94db074bd4&quot;&gt;Fixes an issue where, when using the packet filter-based driver, Zscaler Client Connector added a route for 100.64.0.2 when ZPA connected but did not delete it when ZPA was turned off, which sometimes caused problems with domain profile detection.&lt;/li&gt;&lt;li data-list-item-id=&quot;e581361cb3db52bdbc1a7137a067d7392&quot;&gt;Fixes an issue where, if the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/adding-ruleset#default-outbound&quot; target=&quot;_blank&quot;&gt;Default Outbound Firewall Rule&lt;/a&gt; was set to Firewall Allow in the Zscaler Endpoint Firewall config and &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#firewall&quot; target=&quot;_blank&quot;&gt;Block Domain Profile Detection&lt;/a&gt; was enabled for any network type, the domain profile detection traffic wasn&#039;t blocked as expected after a network change.&lt;/li&gt;&lt;li data-list-item-id=&quot;eb5baf7b1a8f2ddb46f2471359c6fce24&quot;&gt;Fixes a driver issue that could cause process-based bypasses, the Block Domain Profile Detection feature, the captive portal lockdown settings, and &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#zcc-fail-close-settings&quot; target=&quot;_blank&quot;&gt;fail-close settings&lt;/a&gt; to work incorrectly.&lt;/li&gt;&lt;li data-list-item-id=&quot;ecceef9adead0bc2e3c17864e0ff944c0&quot;&gt;Fixes an issue where, if &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-automatic-zpa-reauthentication&quot; target=&quot;_blank&quot;&gt;Automatic ZPA Reauthentication&lt;/a&gt; was enabled and auto reauthentication was initiated after the device woke from sleep, users had to attempt a manual authentication and received a timeout error.&lt;/li&gt;&lt;li data-list-item-id=&quot;e514538011f537f69985fd9c82433825c&quot;&gt;Fixes an issue where, after an application retried DNS requests using the same source port (e.g., due to heavy load or ZPA evaluation), a subsequent DNS request using that source port could be bypassed.&lt;/li&gt;&lt;li data-list-item-id=&quot;e8119d4ca3e2c4fc69dcada0972f24d01&quot;&gt;Fixes a tunnel IP handling issue that caused the VPN (for Legacy Apps) feature to not work, resulting in a blank VPN Tunnel section on the Private Access window in the app.&lt;/li&gt;&lt;li data-list-item-id=&quot;e755a73a7a1e5a1911e9e15f6ef87019a&quot;&gt;Fixes an issue where Zscaler Client Connector didn&#039;t refresh the driver state after the device woke from sleep, causing the app to display a &lt;code&gt;Driver Error&lt;/code&gt; even though it was connected to the Zscaler service.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release in Limited Availability</category>
                                    <version>4.9</version>
                                                <pubDate>Tue, 31 Mar 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1539042 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.7.0.232 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=Windows&amp;applicable_version=4.7.0.232&amp;deployment_date=2026-03-17&amp;id=1538934</link>
                <description>&lt;p class=&quot;note&quot;&gt;This version of Zscaler Client Connector has a known issue affecting the Zscaler Client Connector filter driver. In certain scenarios, the issue could cause the system to enter an error state (display a blue screen) during a Zscaler Client Connector upgrade or system startup. If you encounter this issue, contact Zscaler Support for assistance. The issue has been corrected on Zscaler Client Connector version 4.7.0.317.&lt;/p&gt;&lt;ul&gt;&lt;li data-list-item-id=&quot;e82dc4d51c2861b8927ffa1f2b881577f&quot;&gt;Fixes performance issues that occurred after enabling Hyper-V and creating an external switch with a Wi-Fi adapter.&lt;/li&gt;&lt;li data-list-item-id=&quot;e625cdc5b7a7cfa408669a9996c318877&quot;&gt;Fixes ZSATunnel crash issues that could occur when parsing ClientHello messages.&lt;/li&gt;&lt;li data-list-item-id=&quot;ea6b60bc5e90895cc0e8c5cd2cb307dac&quot;&gt;Fixes a driver issue that could cause the process-based bypass feature, the Block Domain Profile Detection feature, the captive portal lockdown feature, and &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#zcc-fail-close-settings&quot; target=&quot;_blank&quot;&gt;fail-close settings&lt;/a&gt; to work incorrectly.&lt;/li&gt;&lt;li data-list-item-id=&quot;e6c7f2a3b549d25b7e95917fe3e45fae6&quot;&gt;Fixes a tunnel IP handling issue that caused the VPN (for Legacy Apps) feature to not work, resulting in a blank VPN Tunnel section on the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/viewing-information-about-private-access-zscaler-client-connector#win&quot; target=&quot;_blank&quot;&gt;Private Access&lt;/a&gt; window in the app.&lt;/li&gt;&lt;li data-list-item-id=&quot;e6b09a678d6aeb7e91a647de55b752907&quot;&gt;Fixes an issue where Zscaler Client Connector didn&#039;t refresh the driver state after the device woke from sleep, causing the app to display a &lt;code&gt;Driver Error&lt;/code&gt; even though it was connected to the Zscaler service.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.7.0.232</version>
                                                <pubDate>Tue, 17 Mar 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1538934 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.8.0.151 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=Windows&amp;applicable_version=4.8.0.151&amp;deployment_date=2026-03-17&amp;id=1538866</link>
                <description>&lt;p class=&quot;note&quot;&gt;This version of Zscaler Client Connector has a known issue affecting the Zscaler Client Connector filter driver. In certain scenarios, the issue could cause the system to enter an error state (display a blue screen) during a Zscaler Client Connector upgrade or system startup. If you encounter this issue, contact Zscaler Support for assistance. The issue has been corrected on Zscaler Client Connector version 4.8.0.190.&lt;/p&gt;&lt;ul&gt;&lt;li data-list-item-id=&quot;e03d20948e4e33444010174b25720910e&quot;&gt;Fixes performance issues that occurred after enabling Hyper-V and creating an external switch with a Wi-Fi adapter.&lt;/li&gt;&lt;li data-list-item-id=&quot;e90bb4a18b20dc18f918576ab2606238c&quot;&gt;Fixes ZSATunnel crash issues that could occur when parsing ClientHello messages.&lt;/li&gt;&lt;li data-list-item-id=&quot;e3d376d72d90cf84d4853a10e4cabd226&quot;&gt;Fixes an issue where, if the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/adding-ruleset#default-outbound&quot; target=&quot;_blank&quot;&gt;Default Outbound Firewall Rule&lt;/a&gt; was set to Firewall Allow in the Zscaler Endpoint Firewall config and &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#firewall&quot; target=&quot;_blank&quot;&gt;Block Domain Profile Detection&lt;/a&gt; was enabled for any network type, the Block Domain Profile Detection feature was broken.&lt;/li&gt;&lt;li data-list-item-id=&quot;e307957d4118f93ef9f3a5738b4e150ad&quot;&gt;Fixes a driver issue that could cause the process-based bypass feature, the Block Domain Profile Detection feature, the captive portal lockdown feature, and &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#zcc-fail-close-settings&quot; target=&quot;_blank&quot;&gt;fail-close settings&lt;/a&gt; to work incorrectly.&lt;/li&gt;&lt;li data-list-item-id=&quot;e5dcff0f703e625e30465b259a6268d9b&quot;&gt;Fixes an issue where, if &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-automatic-zpa-reauthentication&quot; target=&quot;_blank&quot;&gt;Automatic ZPA Reauthentication&lt;/a&gt; was enabled and auto reauthentication was initiated after the device woke from sleep, users received a timeout error and had to attempt manual authentication.&lt;/li&gt;&lt;li data-list-item-id=&quot;e970eef8044e69806d353d8c00ff87616&quot;&gt;Fixes an issue where DNS requests could be bypassed if, during periods of heavy loading such as connecting to Zscaler Private Access (ZPA), an application retried the requests using the same source port.&lt;/li&gt;&lt;li data-list-item-id=&quot;ede84ed0684cf0bffd6a17240d4c2a212&quot;&gt;Fixes a tunnel IP handling issue that caused the VPN (for Legacy Apps) feature to not work, resulting in a blank VPN Tunnel section on the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/viewing-information-about-private-access-zscaler-client-connector#win&quot; target=&quot;_blank&quot;&gt;Private Access&lt;/a&gt; window in the app.&lt;/li&gt;&lt;li data-list-item-id=&quot;e513278037f667a7caf659c7b5030a302&quot;&gt;Fixes an issue where Zscaler Client Connector didn&#039;t refresh the driver state after the device woke from sleep, causing the app to display a &lt;code&gt;Driver Error&lt;/code&gt; even though it was connected to the Zscaler service.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.8.0.151</version>
                                                <pubDate>Tue, 17 Mar 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1538866 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.6.0.398 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=Windows&amp;applicable_version=4.6.0.398&amp;deployment_date=2026-02-27&amp;id=1538633</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;ea1b72b0e5573c59141d9d28f293907b1&quot;&gt;Supports controlling how Zscaler Client Connector interacts with hardware offloading on network adapters to resolve compatibility issues. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#adv&quot; target=&quot;_blank&quot;&gt;Configuring Zscaler Client Connector App Profiles&lt;/a&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;eb71d90c1768d409445d7788fdf6421c3&quot;&gt;Fixes an issue where Zscaler Client Connector didn’t bypass process-based applications with an environment variable (e.g., &lt;code&gt;%LocalAppData%&lt;/code&gt;) in the application path.&lt;/li&gt;&lt;li data-list-item-id=&quot;e0ba78932282b9ed78a495c06fb888fdf&quot;&gt;Fixes an issue where, if the forwarding profile was set to bypass DNS traffic on a trusted network and send the traffic to Zscaler Private Access (ZPA) on an off-trusted network, network detection caused Zscaler Client Connector to send some DNS traffic to ZPA while on a trusted network.&lt;/li&gt;&lt;li data-list-item-id=&quot;e92b0af1c06aa79b148876987e5d0f250&quot;&gt;Fixes a DNS routing issue that caused connectivity problems for applications accessed over VPN (for Legacy Apps) on a trusted network when the DNS server was defined as an app segment.&lt;/li&gt;&lt;li data-list-item-id=&quot;e01ff0c3dd5af31fb19b09913e39a3588&quot;&gt;Fixes an issue where the legacy SpiderMonkey-based PAC parser didn’t handle single quotations or backslashes correctly, which could result in traffic bypassing the local proxy.&lt;/li&gt;&lt;li data-list-item-id=&quot;ede21ca842afea60ee2f20c11d164e4f4&quot;&gt;Mitigates a vulnerability where specific path validation conditions allowed for elevated write privileges. (CVSS v3.1 Base Score: 6.1 - Medium)&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.6.0.398</version>
                                                <pubDate>Fri, 27 Feb 2026 08:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1538633 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.7.0.223 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=Windows&amp;applicable_version=4.7.0.223&amp;deployment_date=2026-02-27&amp;id=1538581</link>
                <description>&lt;p class=&quot;note&quot;&gt;This version of Zscaler Client Connector has a known issue affecting the Zscaler Client Connector filter driver. In certain scenarios, the issue could cause the system to enter an error state (display a blue screen) during a Zscaler Client Connector upgrade or system startup. If you encounter this issue, contact Zscaler Support for assistance. The issue has been corrected on Zscaler Client Connector version 4.7.0.317.&lt;/p&gt;&lt;ul&gt;&lt;li data-list-item-id=&quot;e51d8c77aac4bce2c0441e57041900a48&quot;&gt;Supports blocking all traffic and allowing only PAC file exclusions when in strict enforcement mode.&lt;/li&gt;&lt;li data-list-item-id=&quot;e208390bb72608d65f9ab106b9635daf2&quot;&gt;Supports controlling how Zscaler Client Connector interacts with hardware offloading on network adapters to resolve compatibility issues.&lt;/li&gt;&lt;li data-list-item-id=&quot;eab380d0e8d81f4f99da03014b0b0e030&quot;&gt;Fixes an issue where trusted network detection using the hostname and IP address criteria could cause a delay in switching between networks when using Zscaler Tunnel (Z-Tunnel) 2.0.&lt;/li&gt;&lt;li data-list-item-id=&quot;ea94a8f679f22575e04145898100d0cfe&quot;&gt;Fixes an issue where Zscaler Client Connector didn’t bypass process-based applications with an environment variable (e.g., &lt;code&gt;%LocalAppData%&lt;/code&gt;) in the application path.&lt;/li&gt;&lt;li data-list-item-id=&quot;eedce8388241959ed0f4d224e0a38fba6&quot;&gt;Mitigates a vulnerability where specific session timeout conditions allowed for the bypass of application exit protections. (CVSS v3.1 Base Score: 3.2 - Low)&lt;/li&gt;&lt;li data-list-item-id=&quot;e82b07c8b27de9db849a8a847c4bbc8cb&quot;&gt;Fixes an issue where, if the forwarding profile was set to bypass DNS traffic on a trusted network and send the traffic to Zscaler Private Access (ZPA) on an off-trusted network, network detection caused Zscaler Client Connector to send some DNS traffic to ZPA while on a trusted network.&lt;/li&gt;&lt;li data-list-item-id=&quot;e3adbc49363c492b68c79c9d0e4562c10&quot;&gt;Fixes a DNS routing issue that caused connectivity problems for applications accessed over VPN (for Legacy Apps) on a trusted network when the DNS server was defined as an app segment.&lt;/li&gt;&lt;li data-list-item-id=&quot;e1784bc53f4a353b813e21fd0b79bee1f&quot;&gt;Fixes an issue where Zscaler Client Connector could bypass traffic on ports 53 and 67.&lt;/li&gt;&lt;li data-list-item-id=&quot;e7cc1ba7338dd4fc85ff89ebb4e15d50e&quot;&gt;Fixes inconsistent behavior where, when reconnecting to a ZPA application through an app segment with the &lt;a href=&quot;https://help.zscaler.com/zpa/configuring-defined-application-segments#define-clientconnector&quot; target=&quot;_blank&quot;&gt;Double Encryption&lt;/a&gt; option enabled, Zscaler Client Connector closed the app client connection immediately instead of holding the connections as it does when the option is disabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;ee7d7b3c941a225334fe4ce5a4efd6cbe&quot;&gt;Fixes an issue where the legacy SpiderMonkey-based PAC parser didn’t handle single quotations or backslashes correctly, which could result in traffic bypassing the local proxy.&lt;/li&gt;&lt;li data-list-item-id=&quot;ed52ffc26909a75d330e07dbf7718c5c3&quot;&gt;Mitigates a vulnerability where specific path validation conditions allowed for elevated write privileges. (CVSS v3.1 Base Score: 6.1 - Medium)&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.7.0.223</version>
                                                <pubDate>Fri, 27 Feb 2026 08:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1538581 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.8.0.140 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=Windows&amp;applicable_version=4.8.0.140&amp;deployment_date=2026-02-26&amp;id=1538637</link>
                <description>&lt;p class=&quot;note&quot;&gt;This version of Zscaler Client Connector has a known issue affecting the Zscaler Client Connector filter driver. In certain scenarios, the issue could cause the system to enter an error state (display a blue screen) during a Zscaler Client Connector upgrade or system startup. If you encounter this issue, contact Zscaler Support for assistance. The issue has been corrected on Zscaler Client Connector version 4.8.0.190.&lt;/p&gt;&lt;ul&gt;&lt;li data-list-item-id=&quot;e98fcf2b59127ab3efcd08860f3c304a8&quot;&gt;Supports blocking all traffic and allowing only PAC file exclusions when in strict enforcement mode. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#pac-proxy&quot; target=&quot;_blank&quot;&gt;Configuring Zscaler Client Connector App Profiles&lt;/a&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;eda880f235ce195303af03fa1f49f03ce&quot;&gt;Supports controlling how Zscaler Client Connector interacts with hardware offloading on network adapters to resolve compatibility issues. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#adv&quot; target=&quot;_blank&quot;&gt;Configuring Zscaler Client Connector App Profiles&lt;/a&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;e6f16e0fca19128cf1624680d87b41a21&quot;&gt;Fixes an issue where trusted network detection using the hostname and IP address criteria could cause a delay in switching between networks when using Zscaler Tunnel (Z-Tunnel) 2.0.&lt;/li&gt;&lt;li data-list-item-id=&quot;e46bcd82449dcf7840e2c8c4df656857a&quot;&gt;Fixes an issue where Zscaler Client Connector didn’t bypass process-based applications with an environment variable (e.g., &lt;code&gt;%LocalAppData%&lt;/code&gt;) in the application path.&lt;/li&gt;&lt;li data-list-item-id=&quot;e52ea4f9a9e9f3288d7d77de60c1400b3&quot;&gt;Mitigates a vulnerability where specific session timeout conditions allowed for the bypass of application exit protections. (CVSS v3.1 Base Score: 3.2 - Low)&lt;/li&gt;&lt;li data-list-item-id=&quot;ef05c8841a39e28369fa8568de88ec9dc&quot;&gt;Fixes an issue where, if the forwarding profile was set to bypass DNS traffic on a trusted network and send the traffic to Zscaler Private Access (ZPA) on an off-trusted network, network detection caused Zscaler Client Connector to send some DNS traffic to ZPA while on a trusted network.&lt;/li&gt;&lt;li data-list-item-id=&quot;e4a7a6e645bcdc8dff130a622238bf03f&quot;&gt;Fixes a DNS routing issue that caused connectivity problems for applications accessed over VPN (for Legacy Apps) on a trusted network when the DNS server was defined as an app segment.&lt;/li&gt;&lt;li data-list-item-id=&quot;e612ca4c259c50acb6debad231268f239&quot;&gt;Fixes an issue where Zscaler Client Connector could bypass traffic on ports 53 and 67.&lt;/li&gt;&lt;li data-list-item-id=&quot;e9ec4ea75d5b6d35afea0e4cca7233cde&quot;&gt;Fixes inconsistent behavior where, when reconnecting to a ZPA application through an app segment with the &lt;a href=&quot;https://help.zscaler.com/zpa/configuring-defined-application-segments#define-clientconnector&quot; target=&quot;_blank&quot;&gt;Double Encryption&lt;/a&gt; option enabled, Zscaler Client Connector closed the app client connection immediately instead of holding the connections as it does when the option is disabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;eb705940d2c7578788e64ef1f767ed9ca&quot;&gt;Fixes an issue where the legacy SpiderMonkey-based PAC parser didn’t handle single quotations or backslashes correctly, which could result in traffic bypassing the local proxy.&lt;/li&gt;&lt;li data-list-item-id=&quot;ec881017770944ac1db9d14da4f4b2754&quot;&gt;Mitigates a vulnerability where specific path validation conditions allowed for elevated write privileges. (CVSS v3.1 Base Score: 6.1 - Medium)&lt;/li&gt;&lt;li data-list-item-id=&quot;e9fc4a7285874ce5f4258453c8e26c8e8&quot;&gt;Fixes an issue where, when using the packet filter-based driver, Zscaler Client Connector added a route for 100.64.0.2 when ZPA connected but did not delete it when ZPA was turned off, which sometimes caused problems with domain profile detection.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.8.0.140</version>
                                                <pubDate>Thu, 26 Feb 2026 08:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1538637 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.6.0.371 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=Windows&amp;applicable_version=4.6.0.371&amp;deployment_date=2026-01-30&amp;id=1535217</link>
                <description>&lt;ul&gt;&lt;li&gt;Supports controlling how Zscaler Client Connector interacts with the Receive Segment Coalescing (RSC) feature on network adapters to resolve compatibility issues. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#adv&quot; target=&quot;_blank&quot;&gt;Configuring Zscaler Client Connector App Profiles&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;Fixes an issue where the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#firewall&quot; target=&quot;_blank&quot;&gt;Block Domain Profile Detection&lt;/a&gt; feature didn&#039;t correctly block domain profile detection when switching to a network type with the feature enabled if the policy also had process-based bypasses enabled.&lt;/li&gt;&lt;li&gt;Fixes an issue where the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#zcc-fail-close-settings&quot; target=&quot;_blank&quot;&gt;Fail Close lockdown settings&lt;/a&gt; didn&#039;t apply along with &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#captive-portal&quot; target=&quot;_blank&quot;&gt;captive portal lockdown&lt;/a&gt; if the policy also had process-based bypasses enabled.&lt;/li&gt;&lt;li&gt;Fixes a timing issue where the custom app profile PAC file was not processed in time at startup, causing traffic to be forced through the default gateway domain without applying the relevant bypasses and rules of the PAC file.&lt;/li&gt;&lt;li&gt;Fixes a proxy authentication issue (recalculation of the nonce value) where, if load balancing was used by the ISP, sites could fail to load when using Zscaler Tunnel (Z-Tunnel) 1.0.&lt;/li&gt;&lt;li&gt;Fixes an issue where traffic to a domain bypassed in the PAC file could be sent to the Zscaler service when an internal Health Check port was reused by another application.&lt;/li&gt;&lt;li&gt;Fixes an issue where Zscaler Client Connector didn&#039;t detect the captive portal when sending Zscaler Internet Access (ZIA) traffic through a proxy defined as a Zscaler Private Access (ZPA) application.&lt;/li&gt;&lt;li&gt;Fixes an issue where, if automatic reauthentication failed, users received a timeout error when manually reauthenticating.&lt;/li&gt;&lt;li&gt;Updates the process check for the Full Disk Encryption device posture to use a more reliable check, preventing incorrect encryption status results.&lt;/li&gt;&lt;li&gt;Fixes a delay when logging in to Windows when Zscaler Client Connector is in strict enforcement and machine tunnel mode.&lt;/li&gt;&lt;li&gt;Fixes an issue that caused an &lt;code&gt;Internal Error&lt;/code&gt; message on the Data Protection window in the app for customers using Endpoint Data Loss Prevention (DLP).&lt;/li&gt;&lt;li&gt;Updates the anti-tampering installation files to add protection to Endpoint DLP internal files.&lt;/li&gt;&lt;li&gt;Fixes an issue where a trusted network defined by the Hostname and IP condition wasn&#039;t detected because the Zscaler Client Connector response included both the &lt;code&gt;CName&lt;/code&gt; and the &lt;code&gt;ipaddress&lt;/code&gt; in the response.&lt;/li&gt;&lt;li&gt;Fixes an issue where the Zscaler proxy wasn&#039;t enforced in accordance with the forwarding profile when the profile was set to Enforce Proxy.&lt;/li&gt;&lt;li&gt;Fixes an issue that could cause FW/AV errors on Windows 11 due to an accumulation of App Container loopback exemptions when the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#pac-proxy&quot; target=&quot;_blank&quot;&gt;Disable Loopback Restriction&lt;/a&gt; option was enabled.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.6.0.371</version>
                                                <pubDate>Fri, 30 Jan 2026 08:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1535217 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.7.0.202 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=Windows&amp;applicable_version=4.7.0.202&amp;deployment_date=2026-01-30&amp;id=1535216</link>
                <description>&lt;ul&gt;&lt;li&gt;Supports controlling how Zscaler Client Connector interacts with the Receive Segment Coalescing (RSC) feature on network adapters to resolve compatibility issues. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#adv&quot; target=&quot;_blank&quot;&gt;Configuring Zscaler Client Connector App Profiles&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;Fixes an issue where the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#firewall&quot; target=&quot;_blank&quot;&gt;Block Domain Profile Detection&lt;/a&gt; feature didn&#039;t correctly block domain profile detection when switching to a network type with the feature enabled if the policy also had process-based bypasses enabled.&lt;/li&gt;&lt;li&gt;Fixes an issue where the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#zcc-fail-close-settings&quot; target=&quot;_blank&quot;&gt;Fail Close lockdown settings&lt;/a&gt; didn&#039;t apply along with &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#captive-portal&quot; target=&quot;_blank&quot;&gt;captive portal lockdown&lt;/a&gt; if the policy also had process-based bypasses enabled.&lt;/li&gt;&lt;li&gt;Fixes an issue where an &lt;code&gt;Internal Error&lt;/code&gt; message displayed after users clicked &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/verifying-access-applications&quot; target=&quot;_blank&quot;&gt;Verify Now&lt;/a&gt; in the Zscaler Client Connector app for step-up authentication for customers using the Zscaler Private Access (ZPA) service and not the Zscaler Internet Access (ZIA) service.&lt;/li&gt;&lt;li&gt;Fixes a timing issue where the custom app profile PAC file was not processed in time at startup, causing traffic to be forced through the default gateway domain without applying the relevant bypasses and rules of the PAC file.&lt;/li&gt;&lt;li&gt;Fixes a proxy authentication issue (recalculation of the nonce value) where, if load balancing was used by the ISP, sites could fail to load when using Zscaler Tunnel (Z-Tunnel) 1.0.&lt;/li&gt;&lt;li&gt;Fixes an issue where traffic to a domain bypassed in the PAC file could be sent to the Zscaler service when an internal Health Check port was reused by another application.&lt;/li&gt;&lt;li&gt;Fixes an issue where Zscaler Client Connector didn&#039;t detect the captive portal when sending ZIA traffic through a proxy defined as a ZPA application.&lt;/li&gt;&lt;li&gt;Fixes an issue with slow throughput that occurred when accessing an SMB (Server Message Block) file share through an app segment with the &lt;a href=&quot;https://help.zscaler.com/zpa/configuring-defined-application-segments#define-clientconnector&quot; target=&quot;_blank&quot;&gt;Double Encryption&lt;/a&gt; option enabled.&lt;/li&gt;&lt;li&gt;Fixes an issue where, if automatic reauthentication failed, users received a timeout error when manually reauthenticating.&lt;/li&gt;&lt;li&gt;Updates the process check for the Full Disk Encryption device posture to use a more reliable check, preventing incorrect encryption status results.&lt;/li&gt;&lt;li&gt;Fixes a delay when logging in to Windows when Zscaler Client Connector is in strict enforcement and machine tunnel mode.&lt;/li&gt;&lt;li&gt;Fixes an issue that caused an &lt;code&gt;Internal Error&lt;/code&gt; message on the Data Protection window in the app for customers using Endpoint Data Loss Prevention (DLP).&lt;/li&gt;&lt;li&gt;Updates the anti-tampering installation files to add protection to Endpoint DLP internal files.&lt;/li&gt;&lt;li&gt;Fixes an issue where a trusted network defined by the Hostname and IP condition wasn&#039;t detected because the Zscaler Client Connector response included both the &lt;code&gt;CName&lt;/code&gt; and the &lt;code&gt;ipaddress&lt;/code&gt; in the response.&lt;/li&gt;&lt;li&gt;Fixes an issue where the Zscaler proxy wasn&#039;t enforced in accordance with the forwarding profile when the profile was set to Enforce Proxy.&lt;/li&gt;&lt;li&gt;Fixes an issue that could cause FW/AV errors on Windows 11 due to an accumulation of App Container loopback exemptions when the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#pac-proxy&quot; target=&quot;_blank&quot;&gt;Disable Loopback Restriction&lt;/a&gt; option was enabled.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.7.0.202</version>
                                                <pubDate>Fri, 30 Jan 2026 08:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1535216 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.8.0.115 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=Windows&amp;applicable_version=4.8.0.115&amp;deployment_date=2026-01-30&amp;id=1535221</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;ebf290f6df3192eb3038116842b382239&quot;&gt;Supports controlling how Zscaler Client Connector interacts with the Receive Segment Coalescing (RSC) feature on network adapters to resolve compatibility issues. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#adv&quot; target=&quot;_blank&quot;&gt;Configuring Zscaler Client Connector App Profiles&lt;/a&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;effeae40c88cf7ca06f1cde6d919b4103&quot;&gt;Fixes an issue where devices with the Domain Joined posture profile always passed the posture check, even if the domain name didn&#039;t match or the device wasn&#039;t domain joined.&lt;/li&gt;&lt;li data-list-item-id=&quot;e0366627030513e8999f02dd3b4f4270b&quot;&gt;Fixes an issue where the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#firewall&quot; target=&quot;_blank&quot;&gt;Block Domain Profile Detection&lt;/a&gt; feature didn&#039;t correctly block domain profile detection when switching to a network type with the feature enabled if the policy also had process-based bypasses enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;e11ff9c1a8be45a89cd0b9f27623dc396&quot;&gt;Fixes an issue where the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#zcc-fail-close-settings&quot; target=&quot;_blank&quot;&gt;Fail Close lockdown settings&lt;/a&gt; didn&#039;t apply along with &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#captive-portal&quot; target=&quot;_blank&quot;&gt;captive portal lockdown&lt;/a&gt; if the policy also had process-based bypasses enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;e968c5b1b1dcba99f578050edb709f1a6&quot;&gt;Fixes an issue where an &lt;code&gt;Internal Error&lt;/code&gt; message displayed after users clicked &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/verifying-access-applications&quot; target=&quot;_blank&quot;&gt;Verify Now&lt;/a&gt; in the Zscaler Client Connector app for step-up authentication for customers using the Zscaler Private Access (ZPA) service and not the Zscaler Internet Access (ZIA) service.&lt;/li&gt;&lt;li data-list-item-id=&quot;e00d230e0197ed95b0c6702214fe5f9ff&quot;&gt;Fixes a timing issue where the custom app profile PAC file was not processed in time at startup, causing traffic to be forced through the default gateway domain without applying the relevant bypasses and rules of the PAC file.&lt;/li&gt;&lt;li data-list-item-id=&quot;e5b4bf9435e1372ce4a49decdbe8ea298&quot;&gt;Fixes an issue where traffic to a domain bypassed in the PAC file could be sent to the Zscaler service when an internal Health Check port was reused by another application.&lt;/li&gt;&lt;li data-list-item-id=&quot;e207f534380e395aa1866a184412a12cc&quot;&gt;Fixes an issue where DLL files created by the installer during a Zscaler Client Connector installation or upgrade in the %temp% directory were blocked by Windows Defender Application Control (WDAC) by adding a system environment variable (&lt;code&gt;BITROCK_TEMP_DLLS_FOLDER&lt;/code&gt;) that points to a specific path where the temporary DLLs are extracted. This path can be added to an allowlist of WDAC policies.&lt;/li&gt;&lt;li data-list-item-id=&quot;e9edddb6218aa254a745cde2032163ae3&quot;&gt;Fixes an issue where Zscaler Client Connector didn&#039;t detect the captive portal when sending ZIA traffic through a proxy defined as a ZPA application.&lt;/li&gt;&lt;li data-list-item-id=&quot;e58b367c4a70bfd35c1636299c86ecc77&quot;&gt;Fixes an issue with slow throughput that occurred when accessing an SMB (Server Message Block) file share through an app segment with the &lt;a href=&quot;https://help.zscaler.com/zpa/configuring-defined-application-segments#define-clientconnector&quot; target=&quot;_blank&quot;&gt;Double Encryption&lt;/a&gt; option enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;e613ff3114baddd4dc7dbb67e510b4c75&quot;&gt;Fixes an issue where, if automatic reauthentication failed, users received a timeout error when manually reauthenticating.&lt;/li&gt;&lt;li data-list-item-id=&quot;ede171b6ba455cb6a94c2d7bf8e25a72b&quot;&gt;Fixes an issue that caused an &lt;code&gt;Internal Error&lt;/code&gt; message on the Data Protection window in the app for customers using Endpoint Data Loss Prevention (DLP).&lt;/li&gt;&lt;li data-list-item-id=&quot;eb2966843951f1e3200a2aeb5f5027e7d&quot;&gt;Updates the anti-tampering installation files to add protection to Endpoint DLP internal files.&lt;/li&gt;&lt;li data-list-item-id=&quot;ee14c1cd7e6e28e0b0902defaed117aff&quot;&gt;Fixes an issue where a trusted network defined by the Hostname and IP condition wasn&#039;t detected because the Zscaler Client Connector response included both the &lt;code&gt;CName&lt;/code&gt; and the &lt;code&gt;ipaddress&lt;/code&gt; in the response.&lt;/li&gt;&lt;li data-list-item-id=&quot;e94750331d8dfe4bb6e4b1c3e66943861&quot;&gt;Fixes an issue where the Zscaler proxy wasn&#039;t enforced in accordance with the forwarding profile when the profile was set to Enforce Proxy.&lt;/li&gt;&lt;li data-list-item-id=&quot;e519a247a960a440679722856e7d9b891&quot;&gt;Fixes an issue that could cause FW/AV errors on Windows 11 due to an accumulation of App Container loopback exemptions when the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#pac-proxy&quot; target=&quot;_blank&quot;&gt;Disable Loopback Restriction&lt;/a&gt; option was enabled.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.8.0.115</version>
                                                <pubDate>Fri, 30 Jan 2026 08:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1535221 at https://help.zscaler.com</guid>
            </item>
            </channel>
</rss>
