<rss version="2.0" xml:base="https://help.zscaler.com/rss-feed/zscaler-client-connector/client-connector-app-release-summary-2026/macOS" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>Client Connector App Release Summary (2026)</title>
        <link>https://help.zscaler.com/rss-feed/zscaler-client-connector/client-connector-app-release-summary-2026/macOS</link>
        <description>Zscaler Client Connector app release summary for updates deployed, per OS and version, in 2026.</description>
        <lastBuildDate>Fri, 02 Oct 2026 16:20:40 +0000</lastBuildDate>
        <language>en-us</language>
        <atom:link href="https://help.zscaler.com/rss-feed/zscaler-client-connector/client-connector-app-release-summary-2026/macOS" rel="self" type="application/rss+xml" />
                            <item>
                <title>Zscaler Client Connector 5.0 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=macOS&amp;applicable_version=5.0&amp;deployment_date=2026-10-01&amp;id=1546150</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;e9d007d26a207c1ca5b70c7d6d1f383be&quot;&gt;Supports immediately restarting Z-Tunnel 2.0 after a device wakes up from sleep regardless of the Reconnect Tunnel on System Wakeup setting in a user&#039;s app profile.&lt;/li&gt;&lt;li data-list-item-id=&quot;e2363f9342917b6bde6a12ead533c9445&quot;&gt;Supports excluding DNS servers from the routing table regardless of the setting in a user&#039;s app profile to improve DNS handling and remove reliance on macOS route injection for DNS bypass logic in Route-Based Traffic Interception mode.&lt;/li&gt;&lt;li data-list-item-id=&quot;eec78a1a797473a0347557f9a44417f8f&quot;&gt;Supports always bypassing DNS requests using the Zscaler Client Connector UDP proxy regardless of the setting in a user&#039;s app profile to improve DNS handling and provide a stable mechanism that is resilient to network changes to handle DNS exclusions without relying on changes in the host route table in Route-based Interception mode.&lt;/li&gt;&lt;li data-list-item-id=&quot;e967ca51c476d7b669d630a19d873892f&quot;&gt;Supports processing DNS queries directly using Zscaler Client Connector&#039;s DNS traffic steering and skipping the internal local proxy server regardless of the setting in a user&#039;s app profile to help prevent FW/AV errors due to DNS processing conflicts with macOS Firewall.&lt;/li&gt;&lt;li data-list-item-id=&quot;e250b3e6b34eea862bd363edbbec7b480&quot;&gt;Adds support to the Prioritize DNS Exclusions over Z-Tunnel 2.0 option in App Profiles to ensure that all DNS requests for domains in Domain Exclusions will not be tunneled through Internet &amp; SaaS. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#mac-DNS&quot; target=&quot;_blank&quot;&gt;Configuring Zscaler Client Connector App Profiles&lt;/a&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;e15f6b4ebd992044e525e0a5e24f91f7d&quot;&gt;Supports displaying a customizable notification to end users who are blocked from a Private Access app due to a failed device posture. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-device-posture-profiles&quot; target=&quot;_blank&quot;&gt;Configuring Device Posture Profiles&lt;/a&gt; and &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-notification-templates-zscaler-client-connector&quot; target=&quot;_blank&quot;&gt;Configuring Notification Templates for Zscaler Client Connector&lt;/a&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;eee8a448cbbdba5304b38c5e29aa2f3c0&quot;&gt;Removes notification support through the macOS Notification Center for end user notifications. All end user notifications are now displayed using the Zscaler Notification Framework, which is enabled by default in Zscaler Client Connector.&lt;/li&gt;&lt;li data-list-item-id=&quot;edeeec6d1042ee9cee9b8fec398c4e03f&quot;&gt;Supports overriding legacy &lt;code&gt;config.ini&lt;/code&gt; configurations with PLIST-based installation parameters.&lt;/li&gt;&lt;li data-list-item-id=&quot;e22a56247a33127ae7548eaabbefdff50&quot;&gt;Supports suppressing the message from Private Access that displays to users when a Private Access policy blocks access to an app. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zpa/configuring-access-policies&quot; target=&quot;_blank&quot;&gt;Configuring Access Policies&lt;/a&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;e91b7f0f665e6966fdba340dbbad7794c&quot;&gt;Adds granularity to restrict Private Access partner logins to &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/enabling-zpa-partner-logins&quot; target=&quot;_blank&quot;&gt;specify which partner tenants&lt;/a&gt; can access your organization&#039;s tenant.&lt;/li&gt;&lt;li data-list-item-id=&quot;e8c779f4340ccd38895166bc5c286bb08&quot;&gt;Supports &lt;a href=&quot;https://help.zscaler.com/client-connector/configuring-zscaler-client-connector-app-profiles&quot; target=&quot;_blank&quot;&gt;partner login settings&lt;/a&gt; on the app profile that can override the global Private Access Partner Logins settings (including entering specific partner domains that you can select on the app) and apply a &lt;a href=&quot;https://help.zscaler.com/client-connector/configuring-device-posture-profiles&quot; target=&quot;_blank&quot;&gt;device posture to partner tenants&lt;/a&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;ec96a7abf658ca0a24dcd819fa6888d92&quot;&gt;Modernizes Zscaler Client Connector to provide users with clear status and actionable, natural-language guidance, while keeping technical details within easy reach if they need to engage Zscaler Support.&lt;/li&gt;&lt;li data-list-item-id=&quot;e5ee720f6fa93fe01229272bf7eb53d7f&quot;&gt;Supports Trusted Network Criteria for new user enrollments with Business Continuity.&lt;/li&gt;&lt;li data-list-item-id=&quot;e07ee66eb7dad75a49fe8178d6b6b7027&quot;&gt;Supports Business Continuity mode for Authentication Service users.&lt;/li&gt;&lt;li data-list-item-id=&quot;edf796eecf54bd620e5b70f520439ee0e&quot;&gt;Supports using machine tunnels in Business Continuity mode to allow devices to stay connected to Private Access apps when the Zscaler cloud is unreachable.&lt;/li&gt;&lt;li data-list-item-id=&quot;ee0ca10b84f65bccb6e15c6f3512ab114&quot;&gt;Supports enabling and disabling Internet &amp; SaaS and Digital Experience remotely via CLI. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/interacting-zscaler-client-connector-remotely&quot; target=&quot;_blank&quot;&gt;Interacting with Zscaler Client Connector Remotely&lt;/a&gt;&lt;a target=&quot;_blank&quot;&gt;.&lt;/a&gt;&lt;/li&gt;&lt;li data-list-item-id=&quot;e1d9a7f4c1638531aa20e454175580c03&quot;&gt;&lt;a target=&quot;_blank&quot;&gt;Adds the &lt;/a&gt;&lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-device-posture-profiles#Server-Validated-Client-Certificate&quot; target=&quot;_blank&quot;&gt;Server Validated Client Certificate&lt;/a&gt; posture type that validates the client certificate against the cloud rather than only checking locally for managed devices.&lt;/li&gt;&lt;li data-list-item-id=&quot;e78210acc99c7071fbf05cb26a5b188b3&quot;&gt;Removes support for the Using JavaScript option used to automatically populate the username in the IdP login page. Zscaler Client Connector will not use JavaScript regardless of the user setting in App Supportability. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-automatic-username-population-idp-authentication&quot; target=&quot;_blank&quot;&gt;Configuring Automatic Username Population for IdP Authentication&lt;/a&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;eb5153035946fdd6d63183145a22b982d&quot;&gt;Adds support for &lt;code&gt;login_hint&lt;/code&gt; SAML attributes to improve the Automatically Populate Username for IdP Authentication feature. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-automatic-username-population-idp-authentication&quot; target=&quot;_blank&quot;&gt;Configuring Automatic Username Population for IdP Authentication&lt;/a&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;e9a83cc6fdef619f7f6f5d88f59ab0b13&quot;&gt;Fixes an issue where Zscaler Client Connector incorrectly displayed disconnection and connection notifications when Strict Enforcement mode was active.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release in Limited Availability</category>
                                    <version>5.0</version>
                                                <pubDate>Thu, 01 Oct 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1546150 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.10.0.36 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=macOS&amp;applicable_version=4.10.0.36&amp;deployment_date=2026-09-30&amp;id=1543119</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;e20cccc8a51a1ba8adc1c45794f684577&quot;&gt;Supports using machine tunnels with Private Access (ZPA) apps when using Transparent Proxy-based Interception. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/deploying-zscaler-client-connector-jamf-pro-macos&quot; target=&quot;_blank&quot;&gt;Deploying Zscaler Client Connector with Jamf Pro for macOS&lt;/a&gt;, &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/deploying-zscaler-client-connector-microsoft-intune-macos&quot; target=&quot;_blank&quot;&gt;Deploying Zscaler Client Connector with Microsoft Intune for macOS&lt;/a&gt;, or &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/deploying-zscaler-client-connector-workspace-one-uem-macos&quot; target=&quot;_blank&quot;&gt;Deploying Zscaler Client Connector with Workspace ONE UEM for macOS&lt;/a&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;e85266a52d890e17041090f0262284363&quot;&gt;Fixes an issue where Zscaler Client Connector repeatedly disconnected and reconnected when the Add Ifscope Route option was enabled in the app profile in Route-based Traffic Interception mode.&lt;/li&gt;&lt;li data-list-item-id=&quot;e9ae5768e52bc5209ddf49975500d0778&quot;&gt;Fixes an issue where Zscaler Client Connector ignored custom PAC URLs when Strict Enforcement mode was enabled while using machine tunnels in Route-based Traffic Interception mode.&lt;/li&gt;&lt;li data-list-item-id=&quot;e344e6b135fa139265f3463031fdac1a0&quot;&gt;Fixes an issue where users intermittently received a &lt;code&gt;DNS_PROBE_FINISHED_NXDOMAIN&lt;/code&gt; error when trying to access existing external sites using Internet &amp; SaaS in Transparent-based Proxy Interception Mode.&lt;/li&gt;&lt;li data-list-item-id=&quot;e1ed3a451115c59aacd0198e3d2900255&quot;&gt;Fixes an issue where the Zscaler CLI was incorrectly reporting an authentication status of &lt;code&gt;AUTHENTICATION_REQUIRED&lt;/code&gt; instead of &lt;code&gt;REGISTRATION_REQUIRED&lt;/code&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;e742d85c1916e789c106cd2a3d7175963&quot;&gt;Fixes an issue where Zscaler Client Connector failed to clear all cached Kerberos tickets when the Force Kerberos Ticket Refresh after Private Access Reauthentication option is enabled in the app profile, prompting unexpected reauthentication.&lt;/li&gt;&lt;li data-list-item-id=&quot;e9855e047074f979118de0da1d1fa0064&quot;&gt;Fixes an issue where the Zscaler Client Connector returns &lt;code&gt;false&lt;/code&gt; for all unsupported postures.&lt;/li&gt;&lt;li data-list-item-id=&quot;ee0d42de7b7f058ff9e9dbb82b374acc0&quot;&gt;Fixes an issue where Zscaler Client Connector did not use the default browser when the app was installed with the &lt;code&gt;externalRedirect&lt;/code&gt; installation parameter set to &lt;code&gt;1&lt;/code&gt; and Authentication Browser Type under Platform Settings was set to Browser-Based Authentication with Default Browser enabled or to WebAuthn Popup Browser.&lt;/li&gt;&lt;li data-list-item-id=&quot;ee352fbf19d63c38ac048314174bc5fde&quot;&gt;Fixes an issue where users were prompted to reauthenticate Private Access even though the Forwarding Profile Action for Private Access for the On-Trusted Network type was set to None.&lt;/li&gt;&lt;li data-list-item-id=&quot;e2d0382245f677ca5c51fba588cfc9db2&quot;&gt;Fixes an issue where users with Transparent Proxy-based Interception mode enabled could not access certain websites in Chromium-based browsers and via &lt;code&gt;curl&lt;/code&gt; when the Custom IP-Based Application Bypass field configured in Zscaler Admin Console contained an empty string.&lt;/li&gt;&lt;li data-list-item-id=&quot;e5b2df320096e57939327885a5bdefacc&quot;&gt;Fixes an issue where users could not load their captive portal due to Zscaler Client Connector failing to detect the portal.&lt;/li&gt;&lt;li data-list-item-id=&quot;ecf80b3604822c895f049b9a293da75b9&quot;&gt;Fixes an issue where Zscaler Client Connector reported an incorrect posture evaluation result for Jamf Trust and marked the device as noncompliant when the app&#039;s Apple App Store signing certificate has expired.&lt;/li&gt;&lt;li data-list-item-id=&quot;ec97dcc2563952ba9c5ee145244ca811c&quot;&gt;Fixes an issue where enrollment could fail with a &lt;code&gt;Domain not Registered (3011)&lt;/code&gt; error when the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/registering-devices-zpa-idp-username&quot; target=&quot;_blank&quot;&gt;Register device with ZPA IDP Username&lt;/a&gt; setting was enabled for customers who don&#039;t use Private Access.&lt;/li&gt;&lt;li data-list-item-id=&quot;e20858c6c37e321cfa88778437f48597f&quot;&gt;Fixes an issue that resulted in FW/AV errors by adding the Process DNS Without Proxy Redirection option to change DNS processing logic. Zscaler recommends enabling this option when using Route-based Traffic Interception. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#mac-DNS&quot; target=&quot;_blank&quot;&gt;Configuring Zscaler Client Connector App Profiles&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.10.0.36</version>
                                                <pubDate>Wed, 30 Sep 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1543119 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.5.2.372 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=macOS&amp;applicable_version=4.5.2.372&amp;deployment_date=2026-09-30&amp;id=1543116</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;ec7b0ef5f7058cd70e0a5614888333d73&quot;&gt;Supports using machine tunnels with Private Access (ZPA) apps when using Transparent Proxy-based Interception. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/deploying-zscaler-client-connector-jamf-pro-macos&quot; target=&quot;_blank&quot;&gt;Deploying Zscaler Client Connector with Jamf Pro for macOS&lt;/a&gt;, &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/deploying-zscaler-client-connector-microsoft-intune-macos&quot; target=&quot;_blank&quot;&gt;Deploying Zscaler Client Connector with Microsoft Intune for macOS&lt;/a&gt;, or &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/deploying-zscaler-client-connector-workspace-one-uem-macos&quot; target=&quot;_blank&quot;&gt;Deploying Zscaler Client Connector with Workspace ONE UEM for macOS&lt;/a&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;e1aba00287e046bb82549379bc158fa74&quot;&gt;Fixes an issue where Zscaler Client Connector repeatedly disconnected and reconnected when the Add Ifscope Route option was enabled in the app profile in Route-based Traffic Interception mode.&lt;/li&gt;&lt;li data-list-item-id=&quot;edf3c292b32cdf131de17fc93b4ae8fe0&quot;&gt;Fixes an issue where Zscaler Client Connector ignored custom PAC URLs when Strict Enforcement mode was enabled while using machine tunnels in Route-based Traffic Interception mode.&lt;/li&gt;&lt;li data-list-item-id=&quot;e3c9de9a8cbc14fae143bb3a7a18a3a1a&quot;&gt;Fixes an issue where users intermittently received a &lt;code&gt;DNS_PROBE_FINISHED_NXDOMAIN&lt;/code&gt; error when trying to access existing external sites using Internet &amp; SaaS in Transparent-based Proxy Interception Mode.&lt;/li&gt;&lt;li data-list-item-id=&quot;e8ace0cc04269cbbb46a7a5623166586b&quot;&gt;Fixes an issue where the Zscaler CLI was incorrectly reporting an authentication status of &lt;code&gt;AUTHENTICATION_REQUIRED&lt;/code&gt; instead of &lt;code&gt;REGISTRATION_REQUIRED&lt;/code&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;efef495ef7dc8e75623fe18b3466fa099&quot;&gt;Fixes an issue where the Zscaler Client Connector returns &lt;code&gt;false&lt;/code&gt; for all unsupported postures.&lt;/li&gt;&lt;li data-list-item-id=&quot;edf227df3ef8801bbe07afaf8d24c193d&quot;&gt;Fixes an issue where users with Transparent Proxy-based Interception mode enabled could not access certain websites in Chromium-based browsers and via &lt;code&gt;curl&lt;/code&gt; when the Custom IP-Based Application Bypass field configured in Zscaler Admin Console contained an empty string.&lt;/li&gt;&lt;li data-list-item-id=&quot;e627805e846d8276a6741fa886da30155&quot;&gt;Fixes an issue where Zscaler Client Connector reported an incorrect posture evaluation result for Jamf Trust and marked the device as noncompliant when the app&#039;s Apple App Store signing certificate has expired.&lt;/li&gt;&lt;li data-list-item-id=&quot;efc686ab8f3a2c3cb3d4df708a6094e06&quot;&gt;Fixes an issue where enrollment could fail with a &lt;code&gt;Domain not Registered (3011)&lt;/code&gt; error when the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/registering-devices-zpa-idp-username&quot; target=&quot;_blank&quot;&gt;Register device with ZPA IDP Username&lt;/a&gt; setting was enabled for customers who don&#039;t use Private Access.&lt;/li&gt;&lt;li data-list-item-id=&quot;e0aa2ad525c7d88d722bb9f5fadd0b453&quot;&gt;Fixes an issue that resulted in FW/AV errors by adding the Process DNS Without Proxy Redirection option to change DNS processing logic. Zscaler recommends enabling this option when using Route-based Traffic Interception. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#mac-DNS&quot; target=&quot;_blank&quot;&gt;Configuring Zscaler Client Connector App Profiles&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.5.2.372</version>
                                                <pubDate>Wed, 30 Sep 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1543116 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.7.0.380 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=macOS&amp;applicable_version=4.7.0.380&amp;deployment_date=2026-09-30&amp;id=1543117</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;e221a69dd137769c594ac84c753fd9d6a&quot;&gt;Supports using machine tunnels with Private Access (ZPA) apps when using Transparent Proxy-based Interception. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/deploying-zscaler-client-connector-jamf-pro-macos&quot; target=&quot;_blank&quot;&gt;Deploying Zscaler Client Connector with Jamf Pro for macOS&lt;/a&gt;, &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/deploying-zscaler-client-connector-microsoft-intune-macos&quot; target=&quot;_blank&quot;&gt;Deploying Zscaler Client Connector with Microsoft Intune for macOS&lt;/a&gt;, or &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/deploying-zscaler-client-connector-workspace-one-uem-macos&quot; target=&quot;_blank&quot;&gt;Deploying Zscaler Client Connector with Workspace ONE UEM for macOS&lt;/a&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;ea02932d23f3d05b51f171d420fe6019a&quot;&gt;Fixes an issue where Zscaler Client Connector repeatedly disconnected and reconnected when the Add Ifscope Route option was enabled in the app profile in Route-based Traffic Interception mode.&lt;/li&gt;&lt;li data-list-item-id=&quot;edc47930e2142fa4f2ff363816165d9d2&quot;&gt;Fixes an issue where Zscaler Client Connector ignored custom PAC URLs when Strict Enforcement mode was enabled while using machine tunnels in Route-based Traffic Interception mode.&lt;/li&gt;&lt;li data-list-item-id=&quot;e6926e245824a18aa5bb7bb27e0a9da37&quot;&gt;Fixes an issue where users intermittently received a &lt;code&gt;DNS_PROBE_FINISHED_NXDOMAIN&lt;/code&gt; error when trying to access existing external sites using Internet &amp; SaaS in Transparent-based Proxy Interception Mode.&lt;/li&gt;&lt;li data-list-item-id=&quot;e56e66d39de7097b34ccc0ec0033daf1e&quot;&gt;Fixes an issue where the Zscaler CLI was incorrectly reporting an authentication status of &lt;code&gt;AUTHENTICATION_REQUIRED&lt;/code&gt; instead of &lt;code&gt;REGISTRATION_REQUIRED&lt;/code&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;e83fa8e54e6870c6a1fee9980f2d1fe37&quot;&gt;Fixes an issue where Zscaler Client Connector did not retain user configuration changes after app restart.&lt;/li&gt;&lt;li data-list-item-id=&quot;e3a771d803244ad2894a882c7883a04d5&quot;&gt;Fixes an issue where Zscaler Client Connector ignored user-configured PAC URLs when attempting to override settings locally.&lt;/li&gt;&lt;li data-list-item-id=&quot;e1f61ed5f97634a73ed1111733ab00b01&quot;&gt;Fixes an issue where the Zscaler Client Connector returns &lt;code&gt;false&lt;/code&gt; for all unsupported postures.&lt;/li&gt;&lt;li data-list-item-id=&quot;e28673bef1b7e642f89df90fb01522dc6&quot;&gt;Fixes an issue where Zscaler Client Connector did not use the default browser when the app was installed with the &lt;code&gt;externalRedirect&lt;/code&gt; installation parameter set to &lt;code&gt;1&lt;/code&gt; and Authentication Browser Type under Platform Settings was set to Browser-Based Authentication with Default Browser enabled or to WebAuthn Popup Browser.&lt;/li&gt;&lt;li data-list-item-id=&quot;e66a736c0f25c3a16fd26aaeb9944eeab&quot;&gt;Fixes an issue where users were prompted to reauthenticate Private Access even though the Forwarding Profile Action for Private Access for the On-Trusted Network type was set to None.&lt;/li&gt;&lt;li data-list-item-id=&quot;edf7a3d2fa39deddb44c03037dfa18033&quot;&gt;Fixes an issue where users with Transparent Proxy-based Interception mode enabled could not access certain websites in Chromium-based browsers and via &lt;code&gt;curl&lt;/code&gt; when the Custom IP-Based Application Bypass field configured in Zscaler Admin Console contained an empty string.&lt;/li&gt;&lt;li data-list-item-id=&quot;e4b0a62ee6b9b101fc47074157dd6ed51&quot;&gt;Fixes an issue where users could not load their captive portal due to Zscaler Client Connector failing to detect the portal.&lt;/li&gt;&lt;li data-list-item-id=&quot;eb2d8a79f89eeb773743129ed666bc25b&quot;&gt;Fixes an issue where Zscaler Client Connector reported an incorrect posture evaluation result for Jamf Trust and marked the device as noncompliant when the app&#039;s Apple App Store signing certificate has expired.&lt;/li&gt;&lt;li data-list-item-id=&quot;ee1988b08abd2f7acf67c73b3934e1934&quot;&gt;Fixes an issue where enrollment could fail with a &lt;code&gt;Domain not Registered (3011)&lt;/code&gt; error when the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/registering-devices-zpa-idp-username&quot; target=&quot;_blank&quot;&gt;Register device with ZPA IDP Username&lt;/a&gt; setting was enabled for customers who don&#039;t use Private Access.&lt;/li&gt;&lt;li data-list-item-id=&quot;efdb1c41e723aac712e901ec3ff460fdc&quot;&gt;Fixes an issue that resulted in FW/AV errors by adding the Process DNS Without Proxy Redirection option to change DNS processing logic. Zscaler recommends enabling this option when using Route-based Traffic Interception. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#mac-DNS&quot; target=&quot;_blank&quot;&gt;Configuring Zscaler Client Connector App Profiles&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.7.0.380</version>
                                                <pubDate>Wed, 30 Sep 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1543117 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.8.0.281 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=macOS&amp;applicable_version=4.8.0.281&amp;deployment_date=2026-09-30&amp;id=1543118</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;eda96834843bb5318d04a92cf59fcaf61&quot;&gt;Supports using machine tunnels with Private Access (ZPA) apps when using Transparent Proxy-based Interception. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/deploying-zscaler-client-connector-jamf-pro-macos&quot; target=&quot;_blank&quot;&gt;Deploying Zscaler Client Connector with Jamf Pro for macOS&lt;/a&gt;, &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/deploying-zscaler-client-connector-microsoft-intune-macos&quot; target=&quot;_blank&quot;&gt;Deploying Zscaler Client Connector with Microsoft Intune for macOS&lt;/a&gt;, or &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/deploying-zscaler-client-connector-workspace-one-uem-macos&quot; target=&quot;_blank&quot;&gt;Deploying Zscaler Client Connector with Workspace ONE UEM for macOS&lt;/a&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;e5d31aac404b64995d2400c3ed541b870&quot;&gt;Fixes an issue where Zscaler Client Connector repeatedly disconnected and reconnected when the Add Ifscope Route option was enabled in the app profile in Route-based Traffic Interception mode.&lt;/li&gt;&lt;li data-list-item-id=&quot;e499007a15dad3a653f19f4d304f4ea1f&quot;&gt;Fixes an issue where Zscaler Client Connector ignored custom PAC URLs when Strict Enforcement mode was enabled while using machine tunnels in Route-based Traffic Interception mode.&lt;/li&gt;&lt;li data-list-item-id=&quot;e5a5c2d41f84d974733a7536152fc50f6&quot;&gt;Fixes an issue where users intermittently received a &lt;code&gt;DNS_PROBE_FINISHED_NXDOMAIN&lt;/code&gt; error when trying to access existing external sites using Internet &amp; SaaS in Transparent-based Proxy Interception Mode.&lt;/li&gt;&lt;li data-list-item-id=&quot;e0e77f99a3ea9a7f0e58335ea026b467f&quot;&gt;Fixes an issue where the Zscaler CLI was incorrectly reporting an authentication status of &lt;code&gt;AUTHENTICATION_REQUIRED&lt;/code&gt; instead of &lt;code&gt;REGISTRATION_REQUIRED&lt;/code&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;e478b304aeed4e6159e3fd6242246088d&quot;&gt;Fixes an issue where Zscaler Client Connector failed to clear all cached Kerberos tickets when the Force Kerberos Ticket Refresh after Private Access Reauthentication option is enabled in the app profile, prompting unexpected reauthentication.&lt;/li&gt;&lt;li data-list-item-id=&quot;e43900c37c7036da263b3349b3b6097cb&quot;&gt;Fixes an issue where Zscaler Client Connector did not retain user configuration changes after app restart.&lt;/li&gt;&lt;li data-list-item-id=&quot;e2525fcf475943ce6714b1a07255ae1ab&quot;&gt;Fixes an issue where Zscaler Client Connector ignored user-configured PAC URLs when attempting to override settings locally.&lt;/li&gt;&lt;li data-list-item-id=&quot;e0113a7223a26ab403149522b452ec60d&quot;&gt;Fixes an issue where the Zscaler Client Connector returns &lt;code&gt;false&lt;/code&gt; for all unsupported postures.&lt;/li&gt;&lt;li data-list-item-id=&quot;e454a6668b330bdbf11fe9aa8e6976552&quot;&gt;Fixes an issue where Zscaler Client Connector did not use the default browser when the app was installed with the &lt;code&gt;externalRedirect&lt;/code&gt; installation parameter set to &lt;code&gt;1&lt;/code&gt; and Authentication Browser Type under Platform Settings was set to Browser-Based Authentication with Default Browser enabled or to WebAuthn Popup Browser.&lt;/li&gt;&lt;li data-list-item-id=&quot;e6c9856df4c642efb4fe238d402c8f27a&quot;&gt;Fixes an issue where users were prompted to reauthenticate Private Access even though the Forwarding Profile Action for Private Access for the On-Trusted Network type was set to None.&lt;/li&gt;&lt;li data-list-item-id=&quot;eccc8bacf43e40dddcf24dacd3de78789&quot;&gt;Fixes an issue where users with Transparent Proxy-based Interception mode enabled could not access certain websites in Chromium-based browsers and via &lt;code&gt;curl&lt;/code&gt; when the Custom IP-Based Application Bypass field configured in Zscaler Admin Console contained an empty string.&lt;/li&gt;&lt;li data-list-item-id=&quot;efb3051ec59963b93636ee719f4c21af5&quot;&gt;Fixes an issue where users could not load their captive portal due to Zscaler Client Connector failing to detect the portal.&lt;/li&gt;&lt;li data-list-item-id=&quot;ef2639de8216b20e458ba1751be5d49ab&quot;&gt;Fixes an issue where Zscaler Client Connector reported an incorrect posture evaluation result for Jamf Trust and marked the device as noncompliant when the app&#039;s Apple App Store signing certificate has expired.&lt;/li&gt;&lt;li data-list-item-id=&quot;ed39426afd0c1ed8aef7aec3f9760e324&quot;&gt;Fixes an issue where enrollment could fail with a &lt;code&gt;Domain not Registered (3011)&lt;/code&gt; error when the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/registering-devices-zpa-idp-username&quot; target=&quot;_blank&quot;&gt;Register device with ZPA IDP Username&lt;/a&gt; setting was enabled for customers who don&#039;t use Private Access.&lt;/li&gt;&lt;li data-list-item-id=&quot;e1693066f890f67477747cb22676ec4ce&quot;&gt;Fixes an issue that resulted in FW/AV errors by adding the Process DNS Without Proxy Redirection option to change DNS processing logic. Zscaler recommends enabling this option when using Route-based Traffic Interception. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#mac-DNS&quot; target=&quot;_blank&quot;&gt;Configuring Zscaler Client Connector App Profiles&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.8.0.281</version>
                                                <pubDate>Wed, 30 Sep 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1543118 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.10 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=macOS&amp;applicable_version=4.10&amp;deployment_date=2026-08-18&amp;id=1542882</link>
                <description>&lt;p&gt;Enables automatic installation of the endpoint software used with Endpoint AI Security through Zscaler Client Connector. To learn more, contact your Zscaler Account team.&lt;/p&gt;</description>
                <category>Release Available</category>
                                    <version>4.10</version>
                                                <pubDate>Tue, 18 Aug 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1542882 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.5.2.355 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=macOS&amp;applicable_version=4.5.2.355&amp;deployment_date=2026-08-12&amp;id=1542684</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;e2f41506795e27112143d981b463a75ee&quot;&gt;Supports using the ind.zscalertwo.net subcloud in the &lt;code&gt;cloudName&lt;/code&gt; installation parameter for Zscaler Client Connector deployments in India.&lt;/li&gt;&lt;li data-list-item-id=&quot;ec379a3f5f2734602c1173bb667355937&quot;&gt;Supports tunneling of ICMP requests to domain-name-based Private Access apps when using Transparent Proxy-based Interception.&lt;/li&gt;&lt;li data-list-item-id=&quot;e8310cc3a719fdf339cf6d2af0538b9b8&quot;&gt;Fixes an issue where Zscaler Client Connector failed to download the partner tenant policy when primary and partner tenants are hosted on different Zscaler clouds.&lt;/li&gt;&lt;li data-list-item-id=&quot;e58a9771458240e866acf2fea6ce240c7&quot;&gt;Fixes an issue where, in a no-default route environment, policy updates were sent directly instead of through the tunnel even though &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#advanced&quot; target=&quot;_blank&quot;&gt;Tunnel Internal Client Connector Traffic&lt;/a&gt; was enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;ed7ca251859847b9c530cef26c9872b00&quot;&gt;Fixes an issue where users could not connect to Private Access apps due to DNS-related caching issues after waking up from sleep when using Transparent Proxy-based Interception.&lt;/li&gt;&lt;li data-list-item-id=&quot;e6dede9a72472b6ca7addd867aac975bc&quot;&gt;Fixes an issue where a Zscaler Client Connector tunnel restarted if a network change occurred while the tunnel was stopped when using Transparent Proxy-based Interception.&lt;/li&gt;&lt;li data-list-item-id=&quot;e906e063997d397e7f3536bfa21aa9f8f&quot;&gt;Fixes an issue where Zscaler Client Connector crashed when users clicked Export Logs.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.5.2.355</version>
                                                <pubDate>Wed, 12 Aug 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1542684 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.7.0.351 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=macOS&amp;applicable_version=4.7.0.351&amp;deployment_date=2026-08-12&amp;id=1542681</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;edad730d422ef2cb37f5e308411dfa83a&quot;&gt;Supports using the ind.zscalertwo.net subcloud in the &lt;code&gt;cloudName&lt;/code&gt; installation parameter for Zscaler Client Connector deployments in India.&lt;/li&gt;&lt;li data-list-item-id=&quot;efacedeb9c73e8a9135286e297178d879&quot;&gt;Supports tunneling of ICMP requests to domain-name-based Private Access apps when using Transparent Proxy-based Interception.&lt;/li&gt;&lt;li data-list-item-id=&quot;ebe5f3619fac68ae24fce9e36fef8f592&quot;&gt;Fixes an issue where Zscaler Client Connector failed to download the partner tenant policy when primary and partner tenants are hosted on different Zscaler clouds.&lt;/li&gt;&lt;li data-list-item-id=&quot;e60c903eaac82f432b1df2abb45ce0a2e&quot;&gt;Fixes an issue where, if &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#mac-pac-proxy&quot; target=&quot;_blank&quot;&gt;Fallback to gateway domain&lt;/a&gt; was selected, Zscaler Client Connector routed traffic to gateway.zscaler.net instead of the subcloud in the cached PAC file after the app restarted.&lt;/li&gt;&lt;li data-list-item-id=&quot;ed7bf578b506ae55722cdd1b4f59c52aa&quot;&gt;Fixes an issue where, in a no-default route environment, policy updates were sent directly instead of through the tunnel even though &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#advanced&quot; target=&quot;_blank&quot;&gt;Tunnel Internal Client Connector Traffic&lt;/a&gt; was enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;ed8c17a5b96396a959a611c3281ab319d&quot;&gt;Fixes an issue where users could not connect to Private Access apps due to DNS-related caching issues after waking up from sleep when using Transparent Proxy-based Interception.&lt;/li&gt;&lt;li data-list-item-id=&quot;ed3d9994171b21f597e178944b8618038&quot;&gt;Fixes an issue where a Zscaler Client Connector tunnel restarted if a network change occurred while the tunnel was stopped when using Transparent Proxy-based Interception.&lt;/li&gt;&lt;li data-list-item-id=&quot;e47e95c341e4fb1cd25de2d66f62c8227&quot;&gt;Fixes an issue where Zscaler Client Connector crashed when users clicked Export Logs.&lt;/li&gt;&lt;li data-list-item-id=&quot;e6edb5705ac92eefa52f107084515756b&quot;&gt;Fixes an issue where Zscaler Client Connector generated abnormally large Transparent Proxy-based Interception logs exceeding 100 MB, causing excessive disk usage.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.7.0.351</version>
                                                <pubDate>Wed, 12 Aug 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1542681 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.8.0.252 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=macOS&amp;applicable_version=4.8.0.252&amp;deployment_date=2026-08-12&amp;id=1542683</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;efd517777135e4f3f961295d190cef699&quot;&gt;Supports using the ind.zscalertwo.net subcloud in the &lt;code&gt;cloudName&lt;/code&gt; installation parameter for Zscaler Client Connector deployments in India.&lt;/li&gt;&lt;li data-list-item-id=&quot;e5681f8982a689f09ff62d8c892f1ca2c&quot;&gt;Supports tunneling of ICMP requests to domain-name-based Private Access apps when using Transparent Proxy-based Interception.&lt;/li&gt;&lt;li data-list-item-id=&quot;ed3c3a9fd029bb718bc6dd1ed3b237162&quot;&gt;Fixes an issue where Zscaler Client Connector failed to download the partner tenant policy when primary and partner tenants are hosted on different Zscaler clouds.&lt;/li&gt;&lt;li data-list-item-id=&quot;e67fb8a484de836e7bdaa74b837a0d362&quot;&gt;Fixes an issue where, if &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#mac-pac-proxy&quot; target=&quot;_blank&quot;&gt;Fallback to gateway domain&lt;/a&gt; was selected, Zscaler Client Connector routed traffic to gateway.zscaler.net instead of the subcloud in the cached PAC file after the app restarted.&lt;/li&gt;&lt;li data-list-item-id=&quot;ea19432e36d165258900692a2d82120de&quot;&gt;Fixes an issue where, in a no-default route environment, policy updates were sent directly instead of through the tunnel even though &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#advanced&quot; target=&quot;_blank&quot;&gt;Tunnel Internal Client Connector Traffic&lt;/a&gt; was enabled.&lt;/li&gt;&lt;li data-list-item-id=&quot;e05c3835d2c2cfa66b187f619067f4438&quot;&gt;Fixes an issue where users could not connect to Private Access apps due to DNS-related caching issues after waking up from sleep when using Transparent Proxy-based Interception.&lt;/li&gt;&lt;li data-list-item-id=&quot;e844eddb25d902387b567c1d9303d185e&quot;&gt;Fixes an issue where a Zscaler Client Connector tunnel restarted if a network change occurred while the tunnel was stopped when using Transparent Proxy-based Interception.&lt;/li&gt;&lt;li data-list-item-id=&quot;e6a3840ee6f675d87c297e281d649f755&quot;&gt;Fixes an issue where Zscaler Client Connector crashed when users clicked Export Logs.&lt;/li&gt;&lt;li data-list-item-id=&quot;e0739040187b502fe2c54fac1328e0ba7&quot;&gt;Fixes an issue where Zscaler Client Connector generated abnormally large Transparent Proxy-based Interception logs exceeding 100 MB, causing excessive disk usage.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.8.0.252</version>
                                                <pubDate>Wed, 12 Aug 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1542683 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.5.2.341 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=macOS&amp;applicable_version=4.5.2.341&amp;deployment_date=2026-07-27&amp;id=1542036</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;e0432a9bfec10a7eb51ca27074b8c97b9&quot;&gt;Fixes an issue where, after the device woke from sleep, Zscaler Client Connector couldn&#039;t immediately connect, which could cause traffic to temporarily be sent directly.&lt;/li&gt;&lt;li data-list-item-id=&quot;ecff791a5c781142e56b378082d6b7424&quot;&gt;Fixes an issue where, if connected using a VPN, Zscaler Client Connector failed to activate &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#mac-ZIA&quot; target=&quot;_blank&quot;&gt;Disaster Recovery for Internet &amp; SaaS&lt;/a&gt; after updating the DNS TXT record value&lt;/li&gt;&lt;li data-list-item-id=&quot;e1dbf6cf37e02d20ff5a47e113d7a62dc&quot;&gt;Fixes an issue where, if &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#mac-advanced&quot; target=&quot;_blank&quot;&gt;Tunnel Internal Client Connector Traffic&lt;/a&gt; was enabled, Zscaler Client Connector didn&#039;t automatically log out after a device was force removed.&lt;/li&gt;&lt;li data-list-item-id=&quot;eb5043f7b9b36144d1f558ef5c2b4e896&quot;&gt;Fixes an issue where users received connection errors after a network change when Transparent Proxy-based Interception was enabled.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.5.2.341</version>
                                                <pubDate>Mon, 27 Jul 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1542036 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.7.0.330 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=macOS&amp;applicable_version=4.7.0.330&amp;deployment_date=2026-07-27&amp;id=1542034</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;e99fdc57468fa03325d80f3502b2442d5&quot;&gt;Fixes an issue where, after the device woke from sleep, Zscaler Client Connector couldn&#039;t immediately connect, which could cause traffic to temporarily be sent directly.&lt;/li&gt;&lt;li data-list-item-id=&quot;ec8ffdbfbf34593b065c1fd2b6833d176&quot;&gt;Fixes an issue where, if connected using a VPN, Zscaler Client Connector failed to activate &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#mac-ZIA&quot; target=&quot;_blank&quot;&gt;Disaster Recovery for Internet &amp; SaaS&lt;/a&gt; after updating the DNS TXT record value&lt;/li&gt;&lt;li data-list-item-id=&quot;e2d14ffc9d2342a075e6fb6cbd4b0a400&quot;&gt;Fixes an issue where, if &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#mac-advanced&quot; target=&quot;_blank&quot;&gt;Tunnel Internal Client Connector Traffic&lt;/a&gt; was enabled, Zscaler Client Connector didn&#039;t automatically log out after a device was force removed.&lt;/li&gt;&lt;li data-list-item-id=&quot;e3fe62ccd59aeb1c474d2ff39d2e1dffb&quot;&gt;Fixes an issue where users received connection errors after a network change when Transparent Proxy-based Interception was enabled.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.7.0.330</version>
                                                <pubDate>Mon, 27 Jul 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1542034 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.8.0.230 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=macOS&amp;applicable_version=4.8.0.230&amp;deployment_date=2026-07-27&amp;id=1542033</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;e39a20f5ea5235d830ba5d35521f4f1d4&quot;&gt;Fixes an issue where, after the device woke from sleep, Zscaler Client Connector couldn&#039;t immediately connect, which could cause traffic to temporarily be sent directly.&lt;/li&gt;&lt;li data-list-item-id=&quot;ebcb35051a953fc619540e9cd44a56b00&quot;&gt;Fixes an issue where, if connected using a VPN, Zscaler Client Connector failed to activate &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#mac-ZIA&quot; target=&quot;_blank&quot;&gt;Disaster Recovery for Internet &amp; SaaS&lt;/a&gt; after updating the DNS TXT record value&lt;/li&gt;&lt;li data-list-item-id=&quot;e3a436ff9158a888d5617faed2841bff5&quot;&gt;Fixes an issue where, if &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#mac-advanced&quot; target=&quot;_blank&quot;&gt;Tunnel Internal Client Connector Traffic&lt;/a&gt; was enabled, Zscaler Client Connector didn&#039;t automatically log out after a device was force removed.&lt;/li&gt;&lt;li data-list-item-id=&quot;e5d00385c21f28c13ffa44111cc41472e&quot;&gt;Fixes an issue where users received connection errors after a network change when Transparent Proxy-based Interception was enabled.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.8.0.230</version>
                                                <pubDate>Mon, 27 Jul 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1542033 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.5.2.334 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=macOS&amp;applicable_version=4.5.2.334&amp;deployment_date=2026-07-15&amp;id=1541773</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;eabb9661add60bd110e2afc672346783b&quot;&gt;Updates the VPN Gateway Bypass to optionally not bypass subdomains for FQDNs. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/bypassing-fqdn-subdomains-vpn-gateway-bypass&quot; target=&quot;_blank&quot; data-entity-type=&quot;node&quot; data-entity-uuid=&quot;c2464d04-b564-408f-89f1-166b5a305837&quot; data-entity-substitution=&quot;canonical&quot;&gt;Bypassing FQDN Subdomains for VPN Gateway Bypass&lt;/a&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;e92a378c35a9d32c5348497730de21e03&quot;&gt;Fixes an issue where Run Zscaler Diagnostics on Zscaler Client Connector never completed or failed to start because the tool incorrectly detected another running instance and prompted for profile installation input during a UI-initiated run.&lt;/li&gt;&lt;li data-list-item-id=&quot;ea2953380ee01161d96a565e909781069&quot;&gt;Fixes an issue where users lost internet connectivity because Internet &amp; SaaS in Transparent Proxy-based Traffic Interception mode entered a tunnel restart rate-limited state and required a device restart to recover.&lt;/li&gt;&lt;li data-list-item-id=&quot;e5c0c3d3c8f7d194b41f8b5a8d3d736bc&quot;&gt;Fixes an issue where Zscaler Client Connector stopped consuming network changes after running for some time.&lt;/li&gt;&lt;li data-list-item-id=&quot;ec148cd6971d5690e7de6fbc9d1663b6a&quot;&gt;Fixes an issue where End User Notifications randomly stopped appearing for Data Loss Prevention (DLP) transactions until the Zscaler Client Connector service was restarted.&lt;/li&gt;&lt;li data-list-item-id=&quot;ec95383ca97433b81d0d4cd1c56803f84&quot;&gt;Fixes an issue where Zscaler Client Connector did not update Private Access with current posture results, causing access failures due to stale unverified posture status.&lt;/li&gt;&lt;li data-list-item-id=&quot;e526bc04d532dea9c8a35e1daf27bb0fb&quot;&gt;Fixes an issue where Internet &amp; SaaS remained disabled despite valid entitlement and policy enforcement until Restart Service selected or Zscaler Client Connector was restarted.&lt;/li&gt;&lt;li data-list-item-id=&quot;eff9e21c11c52864d2ccc17d1917389e3&quot;&gt;Fixes an issue where overlapping Private Access auto-reauthentication flows caused SAML SP PKCE mismatches and displayed an &lt;code&gt;Invalid Response Received&lt;/code&gt; error.&lt;/li&gt;&lt;li data-list-item-id=&quot;e539ae29a10b485acd1adf038f6d149dc&quot;&gt;Fixes an issue where Zscaler Client Connector returned a bad request error during Private Access reauthentication for authentication service for end user migration pilot users.&lt;/li&gt;&lt;li data-list-item-id=&quot;e2562f03ef5c70b6ff77dfebe3f1e2349&quot;&gt;Fixes an issue where Private Access reauthentication did not trigger for migrated users after session expiry, leaving access broken until Zscaler Client Connector was relaunched.&lt;/li&gt;&lt;li data-list-item-id=&quot;ee94aa390dc2c6295a90136cc788b2210&quot;&gt;Fixes an issue where Zscaler Client Connector relied on an unreliable opendirectoryd lookup to detect Active Directory (AD) binding, which caused empty Private Access client-to-client FQDN registration data to be sent when the device was actually AD bound.&lt;/li&gt;&lt;li data-list-item-id=&quot;e386303a209afcba54627342b7bd9eab8&quot;&gt;Fixes an issue where Private Access experienced connectivity failures after Zscaler Client Connector upgrades during device startup or resume from sleep, and provided the Mobile Device Management (MDM) flag disableFirewallHealthCheck to ignore the results of route-based tunnel echo health checks.&lt;/li&gt;&lt;li data-list-item-id=&quot;e8323bd57f8e9fdf82a7bcd993df933ca&quot;&gt;Fixes an issue where posture checks weren’t evaluated correctly for a partner if the domain of the partner tenant is on a different cloud than the main tenant.&lt;/li&gt;&lt;li data-list-item-id=&quot;e91e424042c57c7470d1918c2c54706e1&quot;&gt;Fixes an issue where dedicated IP forwarding traffic was not consistently captured by Internet &amp; SaaS when users switched networks or toggled Wi-Fi, which caused applications to use a non-allowlisted source IP until Zscaler Client Connector was restarted.&lt;br&gt; &lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.5.2.334</version>
                                                <pubDate>Wed, 15 Jul 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1541773 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.7.0.321 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=macOS&amp;applicable_version=4.7.0.321&amp;deployment_date=2026-07-15&amp;id=1541772</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;eabb9661add60bd110e2afc672346783b&quot;&gt;Updates the VPN Gateway Bypass to optionally not bypass subdomains for FQDNs. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/bypassing-fqdn-subdomains-vpn-gateway-bypass&quot; target=&quot;_blank&quot; data-entity-type=&quot;node&quot; data-entity-uuid=&quot;c2464d04-b564-408f-89f1-166b5a305837&quot; data-entity-substitution=&quot;canonical&quot;&gt;Bypassing FQDN Subdomains for VPN Gateway Bypass&lt;/a&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;e92a378c35a9d32c5348497730de21e03&quot;&gt;Fixes an issue where Run Zscaler Diagnostics on Zscaler Client Connector never completed or failed to start because the tool incorrectly detected another running instance and prompted for profile installation input during a UI-initiated run.&lt;/li&gt;&lt;li data-list-item-id=&quot;ea2953380ee01161d96a565e909781069&quot;&gt;Fixes an issue where users lost internet connectivity because Internet &amp; SaaS in Transparent Proxy-based Traffic Interception mode entered a tunnel restart rate-limited state and required a device restart to recover.&lt;/li&gt;&lt;li data-list-item-id=&quot;e5c0c3d3c8f7d194b41f8b5a8d3d736bc&quot;&gt;Fixes an issue where Zscaler Client Connector stopped consuming network changes after running for some time.&lt;/li&gt;&lt;li data-list-item-id=&quot;ec148cd6971d5690e7de6fbc9d1663b6a&quot;&gt;Fixes an issue where End User Notifications randomly stopped appearing for Data Loss Prevention (DLP) transactions until the Zscaler Client Connector service was restarted.&lt;/li&gt;&lt;li data-list-item-id=&quot;ec95383ca97433b81d0d4cd1c56803f84&quot;&gt;Fixes an issue where Zscaler Client Connector did not update Private Access with current posture results, causing access failures due to stale unverified posture status.&lt;/li&gt;&lt;li data-list-item-id=&quot;e526bc04d532dea9c8a35e1daf27bb0fb&quot;&gt;Fixes an issue where Internet &amp; SaaS remained disabled despite valid entitlement and policy enforcement until Restart Service selected or Zscaler Client Connector was restarted.&lt;/li&gt;&lt;li data-list-item-id=&quot;eff9e21c11c52864d2ccc17d1917389e3&quot;&gt;Fixes an issue where overlapping Private Access auto-reauthentication flows caused SAML SP PKCE mismatches and displayed an &lt;code&gt;Invalid Response Received&lt;/code&gt; error.&lt;/li&gt;&lt;li data-list-item-id=&quot;e539ae29a10b485acd1adf038f6d149dc&quot;&gt;Fixes an issue where Zscaler Client Connector returned a bad request error during Private Access reauthentication for authentication service for end user migration pilot users.&lt;/li&gt;&lt;li data-list-item-id=&quot;e2562f03ef5c70b6ff77dfebe3f1e2349&quot;&gt;Fixes an issue where Private Access reauthentication did not trigger for migrated users after session expiry, leaving access broken until Zscaler Client Connector was relaunched.&lt;/li&gt;&lt;li data-list-item-id=&quot;ee94aa390dc2c6295a90136cc788b2210&quot;&gt;Fixes an issue where Zscaler Client Connector relied on an unreliable opendirectoryd lookup to detect Active Directory (AD) binding, which caused empty Private Access client-to-client FQDN registration data to be sent when the device was actually AD bound.&lt;/li&gt;&lt;li data-list-item-id=&quot;e386303a209afcba54627342b7bd9eab8&quot;&gt;Fixes an issue where Private Access experienced connectivity failures after Zscaler Client Connector upgrades during device startup or resume from sleep, and provided the Mobile Device Management (MDM) flag disableFirewallHealthCheck to ignore the results of route-based tunnel echo health checks.&lt;/li&gt;&lt;li data-list-item-id=&quot;e8323bd57f8e9fdf82a7bcd993df933ca&quot;&gt;Fixes an issue where posture checks weren’t evaluated correctly for a partner if the domain of the partner tenant is on a different cloud than the main tenant.&lt;/li&gt;&lt;li data-list-item-id=&quot;e91e424042c57c7470d1918c2c54706e1&quot;&gt;Fixes an issue where dedicated IP forwarding traffic was not consistently captured by Internet &amp; SaaS when users switched networks or toggled Wi-Fi, which caused applications to use a non-allowlisted source IP until Zscaler Client Connector was restarted.&lt;br&gt; &lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.7.0.321</version>
                                                <pubDate>Wed, 15 Jul 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1541772 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.8.0.221 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=macOS&amp;applicable_version=4.8.0.221&amp;deployment_date=2026-07-15&amp;id=1541771</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;eabb9661add60bd110e2afc672346783b&quot;&gt;Updates the VPN Gateway Bypass to optionally not bypass subdomains for FQDNs. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/bypassing-fqdn-subdomains-vpn-gateway-bypass&quot; target=&quot;_blank&quot; data-entity-type=&quot;node&quot; data-entity-uuid=&quot;c2464d04-b564-408f-89f1-166b5a305837&quot; data-entity-substitution=&quot;canonical&quot;&gt;Bypassing FQDN Subdomains for VPN Gateway Bypass&lt;/a&gt;.&lt;/li&gt;&lt;li data-list-item-id=&quot;edeb4f553a58a665385be8631015c26dc&quot;&gt;Fixes an issue where users lost internet connectivity because Internet &amp; SaaS in Transparent Proxy-based Traffic Interception mode entered a tunnel restart rate-limited state and required a device restart to recover.&lt;/li&gt;&lt;li data-list-item-id=&quot;e92f1114cd706b39413ee3a391ad855cc&quot;&gt;Fixes an issue where Zscaler Client Connector stopped consuming network changes after running for some time.&lt;/li&gt;&lt;li data-list-item-id=&quot;ec37803cd8ddbd1bf0bb422b9c5ae7dc1&quot;&gt;Fixes an issue where End User Notifications randomly stopped appearing for Data Loss Prevention (DLP) transactions until the Zscaler Client Connector service was restarted.&lt;/li&gt;&lt;li data-list-item-id=&quot;e23eb7a32cab9510531b43b6a03d855ac&quot;&gt;Fixes an issue where Zscaler Client Connector did not update Private Access with current posture results, causing access failures due to stale unverified posture status.&lt;/li&gt;&lt;li data-list-item-id=&quot;e7fba0253b0d69b4675ce82109a5f81b7&quot;&gt;Fixes an issue where Internet &amp; SaaS remained disabled despite valid entitlement and policy enforcement until Restart Service selected or Zscaler Client Connector was restarted.&lt;/li&gt;&lt;li data-list-item-id=&quot;ed64e89816c7c25cdd967e6573aac83e8&quot;&gt;Fixes an issue where overlapping Private Access auto-reauthentication flows caused SAML SP PKCE mismatches and displayed an &lt;code&gt;Invalid Response Received&lt;/code&gt; error.&lt;/li&gt;&lt;li data-list-item-id=&quot;e9e995c5ff8b9b1a3317347aeed158ac0&quot;&gt;Fixes an issue where Zscaler Client Connector returned a bad request error during Private Access reauthentication for authentication service for end user migration pilot users.&lt;/li&gt;&lt;li data-list-item-id=&quot;ea328d7e7fe44a2695455c07d860255bf&quot;&gt;Fixes an issue where Private Access reauthentication did not trigger for migrated users after session expiry, leaving access broken until Zscaler Client Connector was relaunched.&lt;/li&gt;&lt;li data-list-item-id=&quot;e14bab7e1013a8e4ae0a51adcf9a65d6d&quot;&gt;Fixes an issue where Zscaler Client Connector relied on an unreliable opendirectoryd lookup to detect Active Directory (AD) binding, which caused empty Private Access client-to-client FQDN registration data to be sent when the device was actually AD bound.&lt;/li&gt;&lt;li data-list-item-id=&quot;eb1b86e17d28a69219563128c336d78df&quot;&gt;Fixes an issue where Private Access experienced connectivity failures after Zscaler Client Connector upgrades during device startup or resume from sleep, and provided the Mobile Device Management (MDM) flag disableFirewallHealthCheck to ignore the results of route-based tunnel echo health checks.&lt;/li&gt;&lt;li data-list-item-id=&quot;e29123784fc31d7c338005e079bf56a23&quot;&gt;Fixes an issue where posture checks weren’t evaluated correctly for a partner if the domain of the partner tenant is on a different cloud than the main tenant.&lt;/li&gt;&lt;li data-list-item-id=&quot;eea5ae47d07e839fc6aa4647cc28d47ba&quot;&gt;Fixes an issue where dedicated IP forwarding traffic was not consistently captured by Internet &amp; SaaS when users switched networks or toggled Wi-Fi, which caused applications to use a non-allowlisted source IP until Zscaler Client Connector was restarted.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.8.0.221</version>
                                                <pubDate>Wed, 15 Jul 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1541771 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.5.2.312 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=macOS&amp;applicable_version=4.5.2.312&amp;deployment_date=2026-06-01&amp;id=1540978</link>
                <description>&lt;ul style=&quot;list-style-type:disc;&quot;&gt;&lt;li data-list-item-id=&quot;e2edee37235604a9fdfe5e730581a1a8f&quot;&gt;Mitigates multiple remote code execution vulnerabilities. (CVE-2026-59568)&lt;/li&gt;&lt;li data-list-item-id=&quot;eda58f21eb4025e915c5deee84c70cbcf&quot;&gt;Fixes an authentication bypass issue for Zscaler Client Connector to Zscaler Client Connector Portal-only communications. (CVE-2026-59564)&lt;/li&gt;&lt;li data-list-item-id=&quot;e7067a944f17c7fc49f08ad4a8dde98d9&quot;&gt;Fixes multiple vulnerabilities that allowed for local privilege escalation. (CVE-2026-59567)&lt;/li&gt;&lt;li data-list-item-id=&quot;eae4423ed525ee1dc1d8d361ca456a3f6&quot;&gt;Fixes an issue where posture checks were failing for all postures due to a timeout of the Zero Trust Assessment (ZTA) Score posture.&lt;/li&gt;&lt;li data-list-item-id=&quot;ea377c950efff63fdd30d257b87dd4912&quot;&gt;Fixes an issue where users couldn’t access Zscaler Private Access (ZPA) client applications and encountered a &lt;code&gt;no such host&lt;/code&gt; error with Transparent Proxy-based Traffic Interception.&lt;/li&gt;&lt;li data-list-item-id=&quot;e8797fc066c123a1b11e54685ce6ed8bc&quot;&gt;Fixes an issue where all internet traffic was blocked by Zscaler Client Connector firewall with the enforceTrafficViaTunnel feature enabled and with Transparent Proxy-based Traffic Interception in use.&lt;/li&gt;&lt;li data-list-item-id=&quot;ea14ed21506e87017ede4fa7eb8ca80ec&quot;&gt;Fixes an issue which prevented Zscaler Tunnel (Z-Tunnel) from being established with Zscaler Client Connector in Strict Enforcement mode with Transparent Proxy-based Traffic Interception.&lt;/li&gt;&lt;li data-list-item-id=&quot;e9dc589bd0b7f089a3f511e528bafcf39&quot;&gt;Fixes an issue where Zscaler Client Connector did not display an end user notification for ZPA reauthentication.&lt;/li&gt;&lt;li data-list-item-id=&quot;e5b45cd5e7312c7b2049713016c23682f&quot;&gt;Fixes an issue where users did not receive end user notifications for inline Data Loss Prevention (DLP) events.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.5.2.312</version>
                                                <pubDate>Mon, 01 Jun 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1540978 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.7.0.292 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=macOS&amp;applicable_version=4.7.0.292&amp;deployment_date=2026-06-01&amp;id=1540977</link>
                <description>&lt;ul style=&quot;list-style-type:disc;&quot;&gt;&lt;li data-list-item-id=&quot;e2d886d16fc13cbd2892d5a1cb361c51f&quot;&gt;Mitigates multiple remote code execution vulnerabilities. (CVE-2026-59568)&lt;/li&gt;&lt;li data-list-item-id=&quot;e3ba3bdf6a7032eca3f44bd2fdccf42a2&quot;&gt;Fixes an authentication bypass issue for Zscaler Client Connector to Zscaler Client Connector Portal-only communications. (CVE-2026-59564)&lt;/li&gt;&lt;li data-list-item-id=&quot;e98709e9cbae95466a6eb689a5d6b5460&quot;&gt;Fixes multiple vulnerabilities that allowed for local privilege escalation. (CVE-2026-59567)&lt;/li&gt;&lt;li data-list-item-id=&quot;e17399dc88663f2e847fb3374cf9707af&quot;&gt;Fixes an issue where posture checks were failing for all postures due to a timeout of the Zero Trust Assessment (ZTA) Score posture.&lt;/li&gt;&lt;li data-list-item-id=&quot;e694d46969f51fd07489f2b431bee0ca6&quot;&gt;Fixes an issue where users couldn’t access Zscaler Private Access (ZPA) client applications and encountered a &lt;code&gt;no such host&lt;/code&gt; error with Transparent Proxy-based Traffic Interception.&lt;/li&gt;&lt;li data-list-item-id=&quot;eef7c79f5f7eaf75f40676b1ce9a5e712&quot;&gt;Fixes an issue where all internet traffic was blocked by Zscaler Client Connector firewall with the enforceTrafficViaTunnel feature enabled and with Transparent Proxy-based Traffic Interception in use.&lt;/li&gt;&lt;li data-list-item-id=&quot;e2ec793eaae03b2de8a22b96e76a4e158&quot;&gt;Fixes an issue which prevented Zscaler Tunnel (Z-Tunnel) from being established with Zscaler Client Connector in Strict Enforcement mode with Transparent Proxy-based Traffic Interception.&lt;/li&gt;&lt;li data-list-item-id=&quot;e11e71162671c167577df21a5f7f36b84&quot;&gt;Fixes an issue where Zscaler Client Connector did not display an end user notification for ZPA reauthentication.&lt;/li&gt;&lt;li data-list-item-id=&quot;edd4e42999ae0f1bf31197fd2e1797ff3&quot;&gt;Fixes an issue where users did not receive end user notifications for inline Data Loss Prevention (DLP) events.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.7.0.292</version>
                                                <pubDate>Mon, 01 Jun 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1540977 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.8.0.191 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=macOS&amp;applicable_version=4.8.0.191&amp;deployment_date=2026-06-01&amp;id=1540976</link>
                <description>&lt;ul style=&quot;list-style-type:disc;&quot;&gt;&lt;li data-list-item-id=&quot;e9ac086af435d9fe3e1c361914b2f1c27&quot;&gt;Mitigates multiple remote code execution vulnerabilities. (CVE-2026-59568)&lt;/li&gt;&lt;li data-list-item-id=&quot;e4402353d77fc8365832d99537b087e32&quot;&gt;Fixes an authentication bypass issue for Zscaler Client Connector to Zscaler Client Connector Portal-only communications. (CVE-2026-59564)&lt;/li&gt;&lt;li data-list-item-id=&quot;e98cd481b87c9770f0696b7ffd6d80579&quot;&gt;Fixes multiple vulnerabilities that allowed for local privilege escalation. (CVE-2026-59567)&lt;/li&gt;&lt;li data-list-item-id=&quot;ec4806c5b1096e02282d2320bbb08cb8a&quot;&gt;Fixes an issue where posture checks failed for all postures due to a timeout of the Zero Trust Assessment (ZTA) Score posture.&lt;/li&gt;&lt;li data-list-item-id=&quot;eec32003af250b5e2e4e182fdd445b675&quot;&gt;Fixes an issue where users couldn’t access Zscaler Private Access (ZPA) client applications and encountered a &lt;code&gt;no such host&lt;/code&gt; error with Transparent Proxy-based Traffic Interception.&lt;/li&gt;&lt;li data-list-item-id=&quot;e8dba653777cad0eb0bc00ffa088634f2&quot;&gt;Fixes an issue where all internet traffic was blocked by Zscaler Client Connector firewall with the enforceTrafficViaTunnel feature enabled and with Transparent Proxy-based Traffic Interception in use.&lt;/li&gt;&lt;li data-list-item-id=&quot;e395280de6b3a62b20b6d3f3fb01b209d&quot;&gt;Fixes an issue which prevented Zscaler Tunnel (Z-Tunnel) from being established with Zscaler Client Connector in Strict Enforcement mode with Transparent Proxy-based Traffic Interception.&lt;/li&gt;&lt;li data-list-item-id=&quot;e2fedb55229eef6cceeb263a6b8e1faa9&quot;&gt;Fixes an issue where Zscaler Client Connector did not display an end user notification for ZPA reauthentication.&lt;/li&gt;&lt;li data-list-item-id=&quot;ec268d51804f355be3bde0a06ae20db8a&quot;&gt;Fixes an issue where users did not receive end user notifications for inline Data Loss Prevention (DLP) events.&lt;/li&gt;&lt;li data-list-item-id=&quot;e87fbb30070945422b766c62d46d402fc&quot;&gt;Fixes an issue where end user notifications for inline DLP were not being displayed for Authentication Service (ZIdentity for Users) tenants.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.8.0.191</version>
                                                <pubDate>Mon, 01 Jun 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1540976 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.5.2.251 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=macOS&amp;applicable_version=4.5.2.251&amp;deployment_date=2026-05-15&amp;id=1540725</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;e482a59c9231e29fd5372b93cfb585a8e&quot;&gt;&lt;p dir=&quot;ltr&quot;&gt;Fixes an issue where the Zscaler Private Access (ZPA) partner tunnel failed to start after being stopped, or experiencing an unexpected termination.&lt;/p&gt;&lt;/li&gt;&lt;li data-list-item-id=&quot;e7aee563cb48e96b2cb0edc8e9b2ddcea&quot;&gt;&lt;p dir=&quot;ltr&quot;&gt;Fixes an issue where the tunnel stopped forwarding traffic due to Transparent Proxy-based Traffic Interception being unloaded when connecting to Authentication Service for Users tenants.&lt;/p&gt;&lt;/li&gt;&lt;li data-list-item-id=&quot;e684679e4558d6c42b82e244ce2db5087&quot;&gt;&lt;p dir=&quot;ltr&quot;&gt;Fixes an issue where Zscaler Client Connector intermittently disconnected from Zscaler Internet Access (ZIA) due to DHCP and DNS issues when connecting with Transparent Proxy-based Traffic Interception.&lt;/p&gt;&lt;/li&gt;&lt;li data-list-item-id=&quot;e4e5d8c21222122b068ac5adeb51a35a5&quot;&gt;&lt;p dir=&quot;ltr&quot;&gt;Fixes an issue which caused intermittent DNS resolution problems with an active Cisco AnyConnect VPN tunnel and with Zscaler Client Connector forwarding with Transparent Proxy-based Traffic Interception.&lt;/p&gt;&lt;/li&gt;&lt;li data-list-item-id=&quot;e5582a11dc7b82b1a6a9f1138ea95e385&quot;&gt;&lt;p dir=&quot;ltr&quot;&gt;Fixes an issue where Zscaler Client Connector no longer tunnels traffic after switching from a Trusted to an Untrusted Network.&lt;/p&gt;&lt;/li&gt;&lt;li data-list-item-id=&quot;e32748072cff1372d0e27dbad9fb933e2&quot;&gt;Fixes an issue where users lost network connectivity after Zscaler Client Connector received an updated App Profile policy, which switched traffic interception from route-based to Transparent Proxy-based Traffic Interception.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.5.2.251</version>
                                                <pubDate>Fri, 15 May 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1540725 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.7.0.233 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=macOS&amp;applicable_version=4.7.0.233&amp;deployment_date=2026-05-15&amp;id=1540724</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;e3255366e862e26cbb092258d23add990&quot;&gt;&lt;p dir=&quot;ltr&quot;&gt;Fixes an issue where non-web traffic was bypassed while Transparent Proxy-based Traffic Interception was in use.&lt;/p&gt;&lt;/li&gt;&lt;li data-list-item-id=&quot;e5dfff15895811a66026d62b1e06f27ac&quot;&gt;&lt;p dir=&quot;ltr&quot;&gt;Fixes an issue where the Zscaler Private Access (ZPA) partner tunnel failed to start after being stopped, or experiencing an unexpected termination.&lt;/p&gt;&lt;/li&gt;&lt;li data-list-item-id=&quot;eaa32725545b3afb15a2a1ea9d149d6c9&quot;&gt;&lt;p dir=&quot;ltr&quot;&gt;Fixes an issue where the tunnel stopped forwarding traffic due to Transparent Proxy-based Traffic Interception being unloaded when connecting to Authentication Service for Users tenants.&lt;/p&gt;&lt;/li&gt;&lt;li data-list-item-id=&quot;eb2bb89d934945242f3bc13e9bf5cb7b0&quot;&gt;&lt;p dir=&quot;ltr&quot;&gt;Fixes an issue where Zscaler Client Connector intermittently disconnected from Zscaler Internet Access (ZIA) due to DHCP and DNS issues when connecting with Transparent Proxy-based Traffic Interception.&lt;/p&gt;&lt;/li&gt;&lt;li data-list-item-id=&quot;e5678688014d1ca71b2a997986abfb0dd&quot;&gt;&lt;p dir=&quot;ltr&quot;&gt;Fixes an issue which caused intermittent DNS resolution problems with an active Cisco AnyConnect VPN tunnel and with Zscaler Client Connector forwarding with Transparent Proxy-based Traffic Interception.&lt;/p&gt;&lt;/li&gt;&lt;li data-list-item-id=&quot;e57c2b677d5db0d78d2575d19d26282b7&quot;&gt;&lt;p dir=&quot;ltr&quot;&gt;Fixes an issue where Zscaler Client Connector no longer tunnels traffic after switching from a Trusted to an Untrusted Network.&lt;/p&gt;&lt;/li&gt;&lt;li data-list-item-id=&quot;e8582b039d9b0fc3097efeb9abe849666&quot;&gt;Fixes an issue where users lost network connectivity after Zscaler Client Connector received an updated App Profile policy, which switched traffic interception from route-based to Transparent Proxy-based Traffic Interception.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.7.0.233</version>
                                                <pubDate>Fri, 15 May 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1540724 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.8.0.126 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=macOS&amp;applicable_version=4.8.0.126&amp;deployment_date=2026-05-15&amp;id=1540723</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;ee1f182fa13c90b8e35e34ffaf1c8dc01&quot;&gt;&lt;p&gt;&lt;meta charset=&quot;utf-8&quot;&gt;&lt;/p&gt;&lt;p dir=&quot;ltr&quot;&gt;Fixes an issue where non-web traffic was bypassed while Transparent Proxy-based Traffic Interception was in use.&lt;/p&gt;&lt;/li&gt;&lt;li data-list-item-id=&quot;e48e17ffb287cd110560f30d3829dda6b&quot;&gt;&lt;p dir=&quot;ltr&quot;&gt;Fixes an issue where the Zscaler Private Access (ZPA) partner tunnel failed to start after being stopped, or experiencing an unexpected termination.&lt;/p&gt;&lt;/li&gt;&lt;li data-list-item-id=&quot;e3505edd30d304d43c1f97e521e1c6d5b&quot;&gt;&lt;p dir=&quot;ltr&quot;&gt;Fixes an issue where the tunnel stopped forwarding traffic due to Transparent Proxy-based Traffic Interception being unloaded when connecting to Authentication Service for Users tenants.&lt;/p&gt;&lt;/li&gt;&lt;li data-list-item-id=&quot;e8722016e29663060852eb5b586c74147&quot;&gt;&lt;p dir=&quot;ltr&quot;&gt;Fixes an issue where Zscaler Client Connector intermittently disconnected from Zscaler Internet Access (ZIA) due to DHCP and DNS issues when connecting with Transparent Proxy-based Traffic Interception.&lt;/p&gt;&lt;/li&gt;&lt;li data-list-item-id=&quot;e12bd81a34a2ad2de26bbcae2a150ed44&quot;&gt;&lt;p dir=&quot;ltr&quot;&gt;Fixes an issue which caused intermittent DNS resolution problems with an active Cisco AnyConnect VPN tunnel and with Zscaler Client Connector forwarding with Transparent Proxy-based Traffic Interception.&lt;/p&gt;&lt;/li&gt;&lt;li data-list-item-id=&quot;ed08d17f02354dfb205bea3c491027399&quot;&gt;&lt;p dir=&quot;ltr&quot;&gt;Fixes an issue where Zscaler Client Connector no longer tunnels traffic after switching from a Trusted to an Untrusted Network.&lt;/p&gt;&lt;/li&gt;&lt;li data-list-item-id=&quot;e7e2c26fe06d2083561afb2a7715bf6cb&quot;&gt;Fixes an issue where users lost network connectivity after Zscaler Client Connector received an updated App Profile policy, which switched traffic interception from route-based to Transparent Proxy-based Traffic Interception.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.8.0.126</version>
                                                <pubDate>Fri, 15 May 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1540723 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.5.2.221 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=macOS&amp;applicable_version=4.5.2.221&amp;deployment_date=2026-05-01&amp;id=1540162</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;e5b36162d661810b3c7a2a15fcb104cdb&quot;&gt;Fixes an issue where Google Chrome was able to access websites when Zscaler Tunnel (Z-Tunnel) was in a transient state with &lt;code&gt;enforceTrafficVIaTunnel&lt;/code&gt; parameter enabled for Zscaler Client Connector firewall.&lt;/li&gt;&lt;li data-list-item-id=&quot;e7cdc45641c9dbe05e11bbde9d877860c&quot;&gt;Fixes an issue where Zscaler Client Connector was prompting users with Zscaler Private Access (ZPA) disabled from the primary tenant to re-authenticate after every network change when accessing a Partner tenant.&lt;/li&gt;&lt;li data-list-item-id=&quot;e4ac0a23d8fc04eee888f15e9c6914fbd&quot;&gt;Fixes an issue which caused Zscaler Client Connector to repeatedly prompt the user to re-authenticate with status of &lt;code&gt;Registering device&lt;/code&gt; for Pilot users during Authentication Service for Users tenant migration.&lt;/li&gt;&lt;li data-list-item-id=&quot;e50d56c37cd057226f84b3c151d178e91&quot;&gt;Fixes an issue which caused DHCP requests to fail with Transparent Proxy-based Traffic Interception (TPTI).&lt;/li&gt;&lt;li data-list-item-id=&quot;e454b508147e2b2769a931281360cda6b&quot;&gt;Fixes an issue where routes were being incorrectly added by Zscaler Client Connector when forwarding in Tunnel with Local Proxy mode.&lt;/li&gt;&lt;li data-list-item-id=&quot;ee803267b0836d3455c865a494c45990d&quot;&gt;Fixes an issue where the Forwarding Profile PAC was being set incorrectly on devices using non-default listener ports when forwarding in Tunnel with Local Proxy or Enforce Proxy mode.&lt;/li&gt;&lt;li data-list-item-id=&quot;e9c072f12c554d69c0d80a173f413f5b8&quot;&gt;Fixes an issue which caused non-web traffic connections to close prematurely when forwarding in Z-Tunnel 2.0 mode with TPTI.&lt;/li&gt;&lt;li data-list-item-id=&quot;e08884f2161b73e0c7c44e6f60d1ff48c&quot;&gt;Fixes an issue where the Z-Tunnel process crashed with an &lt;code&gt;EXC_BAD_ACCESS&lt;/code&gt; error when forwarding in TPTI mode.&lt;/li&gt;&lt;li data-list-item-id=&quot;e5352d105917824b7da9d58c50304ff9f&quot;&gt;Fixes an issue where the Zscaler speedtest diagnostic failed to launch Diagnostics in the More window when TPTI is in use.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.5.2.221</version>
                                                <pubDate>Fri, 01 May 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1540162 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.7.0.207 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=macOS&amp;applicable_version=4.7.0.207&amp;deployment_date=2026-05-01&amp;id=1540161</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;e2a7728f21833e5bffa11f2a9ca8ca1ec&quot;&gt;Fixes an issue where Google Chrome was able to access websites when Zscaler Tunnel (Z-Tunnel) was in a transient state with &lt;code&gt;enforceTrafficVIaTunnel&lt;/code&gt; parameter enabled for Zscaler Client Connector firewall.&lt;/li&gt;&lt;li data-list-item-id=&quot;ebbe523b9c751bd8f5a69772180018eea&quot;&gt;Fixes an issue where Zscaler Client Connector was prompting users with Zscaler Private Access (ZPA) disabled from the primary tenant to re-authenticate after every network change when accessing a Partner tenant.&lt;/li&gt;&lt;li data-list-item-id=&quot;eb914c2362545b73c92b780f789ad0403&quot;&gt;Fixes an issue which caused Zscaler Client Connector to repeatedly prompt the user to re-authenticate with status of &lt;code&gt;Registering device&lt;/code&gt; for Pilot users during Authentication Service for Users tenant migration.&lt;/li&gt;&lt;li data-list-item-id=&quot;e80d16e618820411598c65db9ad18a97c&quot;&gt;Fixes an issue which caused DHCP requests to fail with Transparent Proxy-based Traffic Interception (TPTI).&lt;/li&gt;&lt;li data-list-item-id=&quot;ec9b56393f3df58e9680ee0670b99d753&quot;&gt;Fixes an issue where routes were being incorrectly added by Zscaler Client Connector when forwarding in Tunnel with Local Proxy mode.&lt;/li&gt;&lt;li data-list-item-id=&quot;ee0046f61b13fd64b5180d7013d04bd6d&quot;&gt;Fixes an issue where the Forwarding Profile PAC was being set incorrectly on devices using non-default listener ports when forwarding in Tunnel with Local Proxy or Enforce Proxy mode.&lt;/li&gt;&lt;li data-list-item-id=&quot;e181d23513ff2f54bc786ec82f4e4f436&quot;&gt;Fixes an issue which caused non-web traffic connections to close prematurely when forwarding in Z-Tunnel 2.0 mode with TPTI.&lt;/li&gt;&lt;li data-list-item-id=&quot;eb05ddaafec46a6c82fe14f6e6de870fb&quot;&gt;Fixes an issue where the Z-Tunnel process crashed with an &lt;code&gt;EXC_BAD_ACCESS&lt;/code&gt; error when forwarding in TPTI mode.&lt;/li&gt;&lt;li data-list-item-id=&quot;ef33e07986b3ce4abcdaa2dfc7a62f04a&quot;&gt;Fixes an issue where the Zscaler speedtest diagnostic failed to launch Diagnostics in the More window when TPTI is in use.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.7.0.207</version>
                                                <pubDate>Fri, 01 May 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1540161 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.8.0.104 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=macOS&amp;applicable_version=4.8.0.104&amp;deployment_date=2026-05-01&amp;id=1540160</link>
                <description>&lt;ul&gt;&lt;li data-list-item-id=&quot;e4941e1f53175fa44ec84813715acf5fe&quot;&gt;Fixes an issue where Google Chrome was able to access websites when Zscaler Tunnel (Z-Tunnel) was in a transient state with &lt;code&gt;enforceTrafficVIaTunnel&lt;/code&gt; parameter enabled for Zscaler Client Connector firewall.&lt;/li&gt;&lt;li data-list-item-id=&quot;e69aec3a8eb774af74422b81d209853db&quot;&gt;Fixes an issue where Zscaler Client Connector was prompting users with Zscaler Private Access (ZPA) disabled from the primary tenant to re-authenticate after every network change when accessing a Partner tenant.&lt;/li&gt;&lt;li data-list-item-id=&quot;ec3103026d00d325199d85ceaa555477f&quot;&gt;Fixes an issue which caused Zscaler Client Connector to repeatedly prompt the user to re-authenticate with status of &lt;code&gt;Registering device&lt;/code&gt; for Pilot users during Authentication Service for Users tenant migration.&lt;/li&gt;&lt;li data-list-item-id=&quot;ec194098c5f1f60b18a33662290fd439d&quot;&gt;Fixes an issue which caused DHCP requests to fail with Transparent Proxy-based Traffic Interception (TPTI).&lt;/li&gt;&lt;li data-list-item-id=&quot;ee39ec36058b74bf2f884adf5c3ce980f&quot;&gt;Fixes an issue where routes were being incorrectly added by Zscaler Client Connector when forwarding in Tunnel with Local Proxy mode.&lt;/li&gt;&lt;li data-list-item-id=&quot;e99952f12e8e799f82de41bc70700208d&quot;&gt;Fixes an issue where the Forwarding Profile PAC was being set incorrectly on devices using non-default listener ports when forwarding in Tunnel with Local Proxy or Enforce Proxy mode.&lt;/li&gt;&lt;li data-list-item-id=&quot;e2de10f78f8cb373ac74b73c8649ad0d2&quot;&gt;Fixes an issue which caused non-web traffic connections to close prematurely when forwarding in Z-Tunnel 2.0 mode with TPTI.&lt;/li&gt;&lt;li data-list-item-id=&quot;ede9f20f7557413684da329de105b1064&quot;&gt;Fixes an issue where traffic interception failed due to Transparent Proxy-based Traffic process crash.&lt;/li&gt;&lt;li data-list-item-id=&quot;e1c419b221596f5ee0d93b49e542e0064&quot;&gt;Fixes an issue where the Z-Tunnel process crashed with an &lt;code&gt;EXC_BAD_ACCESS&lt;/code&gt; error when forwarding in TPTI mode.&lt;/li&gt;&lt;li data-list-item-id=&quot;ed233931691a149fdda159f5c8302e231&quot;&gt;Fixes an issue where the Zscaler speedtest diagnostic failed to launch Diagnostics in the More window when TPTI is in use.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release in Limited Availability</category>
                                    <version>4.8.0.104</version>
                                                <pubDate>Fri, 01 May 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1540160 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.5.2.201 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=macOS&amp;applicable_version=4.5.2.201&amp;deployment_date=2026-04-03&amp;id=1539493</link>
                <description>&lt;ul&gt;&lt;li&gt;Fixes an issue where the Zscaler speedtest diagnostic failed to launch the More Diagnostics window when Transparent Proxy-based Traffic Interception (TPTI) is in use.&lt;/li&gt;&lt;li&gt;Fixes an issue where posture evaluation for ZPA machine tunnels caused an error after user login.&lt;/li&gt;&lt;li&gt;Fixes an issue where DNS over HTTPS traffic was blocked to local LAN DNS server when TPTI is in use.&lt;/li&gt;&lt;li&gt;Fixes an issue where Zscaler Client Connector did not return NXDomain in order to block iCloud Private Relay with TPTI.&lt;/li&gt;&lt;li&gt;Fixes an issue where the menu bar icon of Zscaler Client Connector incorrectly displayed a red notification when Zscaler Internet Access (ZIA) and ZPA services were operational.&lt;/li&gt;&lt;li&gt;Fixes an issue where DNS queries were tunneled incorrectly when a third-party VPN client was active in split VPN mode when TPTI is in use by disabling DNS search ordering.&lt;/li&gt;&lt;li&gt;Fixes an issue where ZPA displayed an &lt;code&gt;SMZPA_CCC_ZMTP_ACS_INT_ERR&lt;/code&gt; error for ZPA inspected traffic when TPTI is in use.&lt;/li&gt;&lt;li&gt;Fixes an issue where the internet became inaccessible when ZIA is disabled when TPTI is in use.&lt;/li&gt;&lt;li&gt;Fixes an issue where Zscaler Client Connector incorrectly handled an exception caused by an invalid pointer, resulting in an unexpected tunnel failure with TPTI in use.&lt;/li&gt;&lt;li&gt;Fixes an issue where there was high CPU consumption when Zscaler Client Connector was setting up ZPA search domains on the system when TPTI is in use.&lt;/li&gt;&lt;li&gt;Fixes an issue where the TPTI tunnel faces a failure and is disconnected when all other services show as functional.&lt;/li&gt;&lt;li&gt;Fixes an issue where Zscaler Client Connector ignored configured certificate templates when performing posture checks, resulting in the posture check passing even with mismatched templates.&lt;/li&gt;&lt;li&gt;Fixes an issue where the Trusted Network Criteria incorrectly judges a trusted network as a non-trusted network, causing Zscaler Client Connector to keep ZPA active even when running on a trusted network.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.5.2.201</version>
                                                <pubDate>Fri, 03 Apr 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1539493 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.7.0.187 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=macOS&amp;applicable_version=4.7.0.187&amp;deployment_date=2026-04-03&amp;id=1539492</link>
                <description>&lt;ul&gt;&lt;li&gt;Fixes an issue where the Zscaler speedtest diagnostic failed to launch the More Diagnostics window when Transparent Proxy-based Traffic Interception (TPTI) is in use.&lt;/li&gt;&lt;li&gt;Fixes an issue where Zscaler Private Access (ZPA) ReAuth Notification with Advanced Notification sent reauthenticate notices at incorrect times, blocking access to applications and forcing reauthentication before the SAML was set to expire.&lt;/li&gt;&lt;li&gt;Fixes an issue where posture evaluation for ZPA machine tunnels caused an error after user login.&lt;/li&gt;&lt;li&gt;Fixes an issue where DNS over HTTPS traffic was blocked to local LAN DNS server when TPTI is in use.&lt;/li&gt;&lt;li&gt;Fixes an issue where Zscaler Client Connector did not return NXDomain in order to block iCloud Private Relay with TPTI.&lt;/li&gt;&lt;li&gt;Fixes an issue where the menu bar icon of Zscaler Client Connector incorrectly displayed a red notification when Zscaler Internet Access (ZIA) and ZPA services were operational.&lt;/li&gt;&lt;li&gt;Fixes an issue where DNS queries were tunneled incorrectly when a third-party VPN client was active in split VPN mode when TPTI is in use by disabling DNS search ordering.&lt;/li&gt;&lt;li&gt;Fixes an issue where ZPA displayed an &lt;code&gt;SMZPA_CCC_ZMTP_ACS_INT_ERR&lt;/code&gt; error for ZPA inspected traffic when TPTI is in use.&lt;/li&gt;&lt;li&gt;Fixes an issue where the internet became inaccessible when ZIA is disabled when TPTI is in use.&lt;/li&gt;&lt;li&gt;Fixes an issue where Zscaler Client Connector incorrectly handled an exception caused by an invalid pointer, resulting in an unexpected tunnel failure with TPTI in use.&lt;/li&gt;&lt;li&gt;Fixes an issue where there was high CPU consumption when Zscaler Client Connector was setting up ZPA search domains on the system when TPTI is in use.&lt;/li&gt;&lt;li&gt;Fixes an issue where the TPTI tunnel faces a failure and is disconnected when all other services show as functional.&lt;/li&gt;&lt;li&gt;Fixes an issue where Zscaler Client Connector ignored configured certificate templates when performing posture checks, resulting in the posture check passing even with mismatched templates.&lt;/li&gt;&lt;li&gt;Fixes an issue where the Trusted Network Criteria incorrectly judges a trusted network as a non-trusted network, causing Zscaler Client Connector to keep ZPA active even when running on a trusted network.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.7.0.187</version>
                                                <pubDate>Fri, 03 Apr 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1539492 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.8.0.83 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=macOS&amp;applicable_version=4.8.0.83&amp;deployment_date=2026-04-03&amp;id=1539490</link>
                <description>&lt;ul&gt;&lt;li&gt;Fixes an issue where the Zscaler speedtest diagnostic failed to launch the More Diagnostics window when Transparent Proxy-based Traffic Interception (TPTI) is in use.&lt;/li&gt;&lt;li&gt;Fixes an issue where Zscaler Private Access (ZPA) ReAuth Notification with Advanced Notification sent reauthenticate notices at incorrect times, blocking access to applications and forcing reauthentication before the SAML was set to expire.&lt;/li&gt;&lt;li&gt;Fixes an issue where posture evaluation for ZPA machine tunnels caused an error after user login.&lt;/li&gt;&lt;li&gt;Fixes an issue where DNS over HTTPS traffic was blocked to local LAN DNS server when TPTI is in use.&lt;/li&gt;&lt;li&gt;Fixes an issue where Zscaler Client Connector prematurely switched to the secondary ZPA Public Service Edge for customers using &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-forwarding-profiles-zscaler-client-connector#forwarding-profile-action-zpa&quot; target=&quot;_blank&quot;&gt;Dynamic ZPA Service Edge Assignment&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;Fixes an issue where the Private Access and Internet Security windows of the app flickered between On and Off states while reauthenticating ZPA when using TPTI.&lt;/li&gt;&lt;li&gt;Fixes an issue where users received a &lt;code&gt;Failed to Start Diagnostics&lt;/code&gt; error after clicking Run Zscaler Diagnostics on the More window of the app.&lt;/li&gt;&lt;li&gt;Fixes an issue where Zscaler Client Connector did not return NXDomain in order to block iCloud Private Relay with TPTI.&lt;/li&gt;&lt;li&gt;Fixes an issue where the menu bar icon of Zscaler Client Connector incorrectly displayed a red notification when Zscaler Internet Access (ZIA) and ZPA services were operational.&lt;/li&gt;&lt;li&gt;Fixes an issue where DNS queries were tunneled incorrectly when a third-party VPN client was active in split VPN mode when TPTI is in use by disabling DNS search ordering.&lt;/li&gt;&lt;li&gt;Fixes an issue where ZPA displayed an &lt;code&gt;SMZPA_CCC_ZMTP_ACS_INT_ERR&lt;/code&gt; error for ZPA inspected traffic when TPTI is in use.&lt;/li&gt;&lt;li&gt;Fixes an issue where the internet became inaccessible when ZIA is disabled when TPTI is in use.&lt;/li&gt;&lt;li&gt;Fixes an issue where Zscaler Client Connector incorrectly handled an exception caused by an invalid pointer, resulting in an unexpected tunnel failure with TPTI in use.&lt;/li&gt;&lt;li&gt;Fixes an issue where there was high CPU consumption when Zscaler Client Connector was setting up ZPA search domains on the system when TPTI is in use.&lt;/li&gt;&lt;li&gt;Fixes an issue where the TPTI tunnel faces a failure and is disconnected when all other services show as functional.&lt;/li&gt;&lt;li&gt;Fixes an issue where Zscaler Client Connector ignored configured certificate templates when performing posture checks, resulting in the posture check passing even with mismatched templates.&lt;/li&gt;&lt;li&gt;Fixes an issue where the Trusted Network Criteria incorrectly judges a trusted network as a non-trusted network, causing Zscaler Client Connector to keep ZPA active even when running on a trusted network.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release in Limited Availability</category>
                                    <version>4.8.0.83</version>
                                                <pubDate>Fri, 03 Apr 2026 07:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1539490 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.5.2.175 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=macOS&amp;applicable_version=4.5.2.175&amp;deployment_date=2026-03-06&amp;id=1538724</link>
                <description>&lt;ul&gt;&lt;li&gt;Fixes an issue where, if the Redirect Web Traffic to Zscaler Client Connector Listening Proxy and Transparent Proxy-based Interception options were enabled, Digital Experience (ZDX) Web probe requests were sent to Zscaler Internet Access (ZIA) even though the app profile PAC file was set to bypass the traffic.&lt;/li&gt;&lt;li&gt;Fixes an issue where users received a &lt;code&gt;Failed to Start Diagnostics&lt;/code&gt; error after clicking &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/troubleshooting-zscaler-client-connector&quot; target=&quot;_blank&quot;&gt;Run Zscaler Diagnostics&lt;/a&gt; on the More window of the app.&lt;/li&gt;&lt;li&gt;Fixes an issue where, after detecting a captive portal and disabling services temporarily, Zscaler Client Connector sent traffic directly instead of based on the app failover settings.&lt;/li&gt;&lt;li&gt;Fixes an issue that caused the OS Version device posture check to fail after upgrading to macOS 26.2.&lt;/li&gt;&lt;li&gt;Fixes an issue where Zscaler Client Connector consumed high CPU resources when connected to Zscaler Private Access (ZPA) while using Transparent Proxy-based Traffic Interception.&lt;/li&gt;&lt;li&gt;Fixes an issue where the Private Access and Internet Security windows of the app flickered between On and Off states while reauthenticating ZPA when using Transparent Proxy-based Traffic Interception.&lt;/li&gt;&lt;li&gt;Removed the trailing whitespace used by Zscaler Client Connector in the &lt;code&gt;user-agent&lt;/code&gt; string.&lt;/li&gt;&lt;li&gt;Fixes a memory consumption issue that resulted in Zscaler Client Connector not connecting after the device woke from sleep when using Transparent Proxy-based Traffic Interception.&lt;/li&gt;&lt;li&gt;Fixes an issue that resulted in a tunnel crash when using Transparent Proxy-based Traffic Interception.&lt;/li&gt;&lt;li&gt;Fixes an issue which caused Kerberos SSO to fail when using Transparent Proxy-based Traffic Interception.&lt;/li&gt;&lt;li&gt;Fixes an issue where Zscaler Client Connector prematurely switched to the secondary ZPA Public Service Edge for customers using &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-forwarding-profiles-zscaler-client-connector#forwarding-profile-action-zpa&quot; target=&quot;_blank&quot;&gt;Dynamic ZPA Service Edge Assignment&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.5.2.175</version>
                                                <pubDate>Fri, 06 Mar 2026 08:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1538724 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.7.0.155 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=macOS&amp;applicable_version=4.7.0.155&amp;deployment_date=2026-03-06&amp;id=1538723</link>
                <description>&lt;ul&gt;&lt;li&gt;Fixes an issue where, if the Redirect Web Traffic to Zscaler Client Connector Listening Proxy and Transparent Proxy-based Interception options were enabled, Digital Experience (ZDX) Web probe requests were sent to Zscaler Internet Access (ZIA) even though the app profile PAC file was set to bypass the traffic.&lt;/li&gt;&lt;li&gt;Fixes a memory consumption issue that resulted in Zscaler Client Connector not connecting after the device woke from sleep when using Transparent Proxy-based Traffic Interception.&lt;/li&gt;&lt;li&gt;Fixes an issue where users received a &lt;code&gt;Failed to Start Diagnostics&lt;/code&gt; error after clicking &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/troubleshooting-zscaler-client-connector&quot; target=&quot;_blank&quot;&gt;Run Zscaler Diagnostics&lt;/a&gt; on the More window of the app.&lt;/li&gt;&lt;li&gt;Fixes an issue where, after detecting a captive portal and disabling services temporarily, Zscaler Client Connector sent traffic directly instead of based on the app failover settings.&lt;/li&gt;&lt;li&gt;Fixes an issue that caused the OS Version device posture check to fail after upgrading to macOS 26.2.&lt;/li&gt;&lt;li&gt;Fixes an issue where Zscaler Client Connector consumed high CPU resources when connected to Zscaler Private Access (ZPA) while using Transparent Proxy-based Traffic Interception.&lt;/li&gt;&lt;li&gt;Fixes an issue where some domains (e.g., google.com) were inaccessible after turning off ZIA.&lt;/li&gt;&lt;li&gt;Fixes an issue where the Private Access and Internet Security windows of the app flickered between On and Off states while reauthenticating ZPA when using Transparent Proxy-based Traffic Interception.&lt;/li&gt;&lt;li&gt;Removed the trailing whitespace used by Zscaler Client Connector in the &lt;code&gt;user-agent&lt;/code&gt; string.&lt;/li&gt;&lt;li&gt;Fixes an issue which caused Kerberos SSO to fail when using Transparent Proxy-based Traffic Interception.&lt;/li&gt;&lt;li&gt;Fixes an issue where Zscaler Client Connector prematurely switched to the secondary ZPA Public Service Edge for customers using &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-forwarding-profiles-zscaler-client-connector#forwarding-profile-action-zpa&quot; target=&quot;_blank&quot;&gt;Dynamic ZPA Service Edge Assignment&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.7.0.155</version>
                                                <pubDate>Fri, 06 Mar 2026 08:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1538723 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.8 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=macOS&amp;applicable_version=4.8&amp;deployment_date=2026-03-02&amp;id=1538618</link>
                <description>&lt;p class=&quot;note&quot;&gt;This version of Zscaler Client Connector has a known issue where Zscaler Client Connector prematurely switched to the secondary ZPA Public Service Edge for customers using &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-forwarding-profiles-zscaler-client-connector#forwarding-profile-action-zpa&quot; target=&quot;_blank&quot;&gt;Dynamic ZPA Service Edge Assignment&lt;/a&gt;. This issue has been corrected on Zscaler Client Connector version 4.8.0.83.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Supports Authentication Service integration for the following features: using Digital Experience (ZDX) without Zscaler Internet Access (ZIA) or Zscaler Private Access (ZPA), reverting to earlier versions, using device groups, machine tunnel authentication, using one-time passwords (OTPs), quarantining devices, and displaying the service disable reason. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zidentity/what-zidentity&quot; target=&quot;_blank&quot;&gt;What is Authentication Service&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;Enhances the CrowdStrike ZTA posture by introducing two new &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-device-posture-profiles&quot; target=&quot;_blank&quot;&gt;device posture checks&lt;/a&gt;: CrowdStrike ZTA Device OS Score and CrowdStrike ZTA Sensor Setting Score.&lt;/li&gt;&lt;li&gt;Supports forcing a Kerberos ticket refresh after ZPA reauthentication. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#mac-adv&quot; data-entity-type=&quot;external&quot;&gt;Configuring Zscaler Client Connector App Profiles&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;Adds failover settings to the app profile that can override the global fail over settings. To learn more, see &lt;a href=&quot;https://help.zscaler.com/client-connector/configuring-zscaler-client-connector-app-profiles&quot; data-entity-type=&quot;external&quot;&gt;Configuring Zscaler Client Connector App Profiles&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;Supports a device posture check for specific Zscaler Client Connector versions. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-device-posture-profiles&quot; target=&quot;_blank&quot;&gt;Configuring Device Posture Profiles&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;Supports process-based application bypass using custom application bypasses defined in the Zscaler Client Connector Portal when you use Transparent Proxy-based Traffic Interception. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/adding-process-based-applications-bypass-traffic&quot; target=&quot;_blank&quot;&gt;Adding Process-Based Applications to Bypass Traffic&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;Supports a new traffic forwarding action for ZIA Disaster Recovery so you can forward traffic using Zscaler Tunnel (Z-Tunnel) 2.0. To learn more, see &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-app-profiles#mac-ZIA&quot; target=&quot;_blank&quot;&gt;Configuring Zscaler Client Connector App Profiles&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;Fixes an issue where a Authentication Service user could not log in to Zscaler Client Connector if their login name included a special character (e.g., # or @).&lt;/li&gt;&lt;li&gt;Fixes an issue where Zscaler Client Connector caused excessive battery usage with ZDX when using ZDX Module version 4.5 and earlier.&lt;/li&gt;&lt;li&gt;Fixes an issue where Zscaler Client Connector failed to re-enroll after the ZPA certificate expired with Authentication Service.&lt;/li&gt;&lt;li&gt;Fixes an issue where the &lt;code&gt;Zscaler would like to use your current location&lt;/code&gt; pop-up message displayed when it should not have because the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-zscaler-client-connector-collect-zdx-location-information&quot; target=&quot;_blank&quot;&gt;Collect Location Info for ZDX&lt;/a&gt; option was disabled.&lt;/li&gt;&lt;li&gt;Fixes delays with single sign-on using browser-based authentication for devices with Auto Proxy Discovery enabled and using Transparent Proxy-based Traffic Interception.&lt;/li&gt;&lt;li&gt;Fixes a case sensitivity issue that caused a Domain Joined device posture check to fail, even though the domain matched.&lt;/li&gt;&lt;li&gt;Fixes an issue that caused the OS Version device posture check to fail for a machine tunnel even though the device used the correct OS version.&lt;/li&gt;&lt;li&gt;Fixes an issue where, after disabling ZIA, an old PAC file was restored instead of the one applied by the Jamf Pro deployment when users had Transparent Proxy-based Traffic Interception enabled with the Cache System Proxy option enabled.&lt;/li&gt;&lt;li&gt;Fixes a connection delay to ZPA that occurred when, after disabling ZPA, a user clicked Turn On if the user had a custom profile for VPN (for Legacy Apps) enabled.&lt;/li&gt;&lt;li&gt;Fixes a connection delay to Zscaler Client Connector that occurred after a device woke up from being idle for a long time or after a restart.&lt;/li&gt;&lt;li&gt;Fixes an issue where, after users clicked Run Zscaler Diagnostics on the More window in the app, the process took a long time to run or became stuck.&lt;/li&gt;&lt;li&gt;Fixes an issue where the Policy Name on the Device Management page was not updated correctly for Authentication Service users with an app profile applied by device group.&lt;/li&gt;&lt;li&gt;Fixes an issue where, if Device Groups are used for ZPA service entitlement, ZPA wasn&#039;t enabled for a user who logged in to the macOS device after another user logged out.&lt;/li&gt;&lt;li&gt;Fixes an issue where, if the Redirect Web Traffic to Zscaler Client Connector Listening Proxy and Transparent Proxy-based Traffic Interception options were enabled, ZDX Web probe requests were sent to ZIA even though the app profile PAC file was set to bypass the traffic.&lt;/li&gt;&lt;li&gt;Fixes an issue that caused the OS Version device posture check to fail after upgrading Zscaler Client Connector until the next successful policy update.&lt;/li&gt;&lt;li&gt;Fixes an issue where, after detecting a captive portal and disabling services temporarily, Zscaler Client Connector sent traffic directly instead of based on the app failover settings.&lt;/li&gt;&lt;li&gt;Fixes an issue that caused the OS Version device posture check to fail after upgrading to macOS 26.2.&lt;/li&gt;&lt;li&gt;Fixes an issue where some domains (e.g., google.com) were inaccessible after turning off ZIA.&lt;/li&gt;&lt;li&gt;Removed the trailing whitespace used by Zscaler Client Connector in the &lt;code&gt;user-agent&lt;/code&gt; string.&lt;/li&gt;&lt;li&gt;Fixes an issue which caused Kerberos SSO to fail when using Transparent Proxy-based Traffic Interception.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release in Limited Availability</category>
                                    <version>4.8</version>
                                                <pubDate>Mon, 02 Mar 2026 08:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1538618 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.5.2.158 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=macOS&amp;applicable_version=4.5.2.158&amp;deployment_date=2026-02-12&amp;id=1538431</link>
                <description>&lt;p class=&quot;note&quot;&gt;This version of Zscaler Client Connector has a known issue where Zscaler Client Connector prematurely switched to the secondary ZPA Public Service Edge for customers using &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-forwarding-profiles-zscaler-client-connector#forwarding-profile-action-zpa&quot; target=&quot;_blank&quot;&gt;Dynamic ZPA Service Edge Assignment&lt;/a&gt;. This issue has been corrected on Zscaler Client Connector version 4.5.2.175.&lt;/p&gt;&lt;p&gt;Fixes an issue that caused the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-device-posture-profiles#OS-Version&quot; target=&quot;_blank&quot;&gt;OS Version&lt;/a&gt; device posture check to fail after upgrading Zscaler Client Connector until the next successful policy update.&lt;/p&gt;</description>
                <category>Release Available</category>
                                    <version>4.5.2.158</version>
                                                <pubDate>Thu, 12 Feb 2026 08:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1538431 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.7.0.134 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=macOS&amp;applicable_version=4.7.0.134&amp;deployment_date=2026-02-12&amp;id=1538430</link>
                <description>&lt;p class=&quot;note&quot;&gt;This version of Zscaler Client Connector has a known issue where Zscaler Client Connector prematurely switched to the secondary ZPA Public Service Edge for customers using &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-forwarding-profiles-zscaler-client-connector#forwarding-profile-action-zpa&quot; target=&quot;_blank&quot;&gt;Dynamic ZPA Service Edge Assignment&lt;/a&gt;. This issue has been corrected on Zscaler Client Connector version 4.7.0.155.&lt;/p&gt;&lt;p&gt;Fixes an issue that caused the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-device-posture-profiles#OS-Version&quot; target=&quot;_blank&quot;&gt;OS Version&lt;/a&gt; device posture check to fail after upgrading Zscaler Client Connector until the next successful policy update.&lt;/p&gt;</description>
                <category>Release Available</category>
                                    <version>4.7.0.134</version>
                                                <pubDate>Thu, 12 Feb 2026 08:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1538430 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.5.2.153 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=macOS&amp;applicable_version=4.5.2.153&amp;deployment_date=2026-02-09&amp;id=1535342</link>
                <description>&lt;div class=&quot;note&quot;&gt;&lt;p&gt;This version of Zscaler Client Connector has a known issue where Zscaler Client Connector prematurely switched to the secondary ZPA Public Service Edge for customers using &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-forwarding-profiles-zscaler-client-connector#forwarding-profile-action-zpa&quot; target=&quot;_blank&quot;&gt;Dynamic ZPA Service Edge Assignment&lt;/a&gt;. This issue has been corrected on Zscaler Client Connector version 4.5.2.175.&lt;/p&gt;&lt;p&gt;This version of Zscaler Client Connector has a known issue that causes the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-device-posture-profiles#OS-Version&quot; target=&quot;_blank&quot;&gt;OS Version&lt;/a&gt; device posture check to fail after upgrading Zscaler Client Connector until the next successful policy update. The issue has been corrected on Zscaler Client Connector version 4.5.2.158.&lt;/p&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;Fixes an issue where Zscaler Client Connector caused excessive battery usage with Digital Experience (ZDX) when using ZDX Module version 4.5 and earlier.&lt;/li&gt;&lt;li&gt;Fixes an issue where Xcode to iOS device communication was blocked when users had Transparent Proxy-based Interception enabled.&lt;/li&gt;&lt;li&gt;Fixes an issue where users were unexpectedly logged out of Zscaler Client Connector after a period of inactivity, requiring them to log in again upon returning.&lt;/li&gt;&lt;li&gt;Fixes a case sensitivity issue that caused a &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-device-posture-profiles#Domain-Joined&quot; target=&quot;_blank&quot;&gt;Domain Joined&lt;/a&gt; device posture check to fail, even though the domain matched.&lt;/li&gt;&lt;li&gt;Fixes an issue that prevented logging in to Zscaler Client Connector due to a DNS error caused by incorrect keychain data after upgrading to macOS Tahoe in Strict Enforcement mode.&lt;/li&gt;&lt;li&gt;Fixes an issue that caused the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-device-posture-profiles#OS-Version&quot; target=&quot;_blank&quot;&gt;OS Version&lt;/a&gt; device posture check to fail for a machine tunnel even though the device was the correct OS version.&lt;/li&gt;&lt;li&gt;Fixes an issue where, after disabling Zscaler Internet Access (ZIA), an old PAC file was restored instead of the one applied by the Jamf Pro deployment when users had Transparent Proxy-based Interception enabled with the Cache System Proxy option enabled.&lt;/li&gt;&lt;li&gt;Fixes a connection delay to Zscaler Private Access (ZPA) that occurred when, after disabling ZPA, a user clicked Turn On if the user had a custom profile for VPN (for Legacy Apps) enabled.&lt;/li&gt;&lt;li&gt;Fixes a connection delay to Zscaler Client Connector that occurred after a device woke up from being idle for a long time or after a restart.&lt;/li&gt;&lt;li&gt;Fixes an issue where, after users clicked Run Zscaler Diagnostics on the More window in the app, the process took a long time to run or became stuck.&lt;/li&gt;&lt;li&gt;Fixes an issue where Zscaler Client Connector in Transparent Proxy-based Interception (TRP) mode added routes incorrectly resulting in connection errors to applications bypassed using IP-based Application Bypass.&lt;/li&gt;&lt;li&gt;Fixes an issue where, if &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/enabling-zpa-device-groups&quot; target=&quot;_blank&quot;&gt;Device Groups&lt;/a&gt; are used for ZPA service entitlement, ZPA wasn&#039;t enabled for a user who logged in to the macOS device after another user logged out.&lt;/li&gt;&lt;li&gt;Fixes an issue where Zscaler Client Connector didn’t accept some DNS query record types (e.g., CNAME), resulting in some domains not being tunneled.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.5.2.153</version>
                                                <pubDate>Mon, 09 Feb 2026 08:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1535342 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.7.0.126 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=macOS&amp;applicable_version=4.7.0.126&amp;deployment_date=2026-02-09&amp;id=1535385</link>
                <description>&lt;div class=&quot;note&quot;&gt;&lt;p&gt;This version of Zscaler Client Connector has a known issue where Zscaler Client Connector prematurely switched to the secondary ZPA Public Service Edge for customers using &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-forwarding-profiles-zscaler-client-connector#forwarding-profile-action-zpa&quot; target=&quot;_blank&quot;&gt;Dynamic ZPA Service Edge Assignment&lt;/a&gt;. This issue has been corrected on Zscaler Client Connector version 4.7.0.155.&lt;/p&gt;&lt;p&gt;This version of Zscaler Client Connector has a known issue that causes the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-device-posture-profiles#OS-Version&quot; target=&quot;_blank&quot;&gt;OS Version&lt;/a&gt; device posture check to fail after upgrading Zscaler Client Connector until the next successful policy update. The issue has been corrected on Zscaler Client Connector version 4.7.0.134.&lt;/p&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;Fixes an issue where Zscaler Client Connector caused excessive battery usage with Digital Experience (ZDX) when using ZDX Module version 4.5 and earlier.&lt;/li&gt;&lt;li&gt;Fixes an issue where Xcode to iOS device communication was blocked when users had Transparent Proxy-based Interception enabled.&lt;/li&gt;&lt;li&gt;Fixes a case sensitivity issue that caused a &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-device-posture-profiles#Domain-Joined&quot; target=&quot;_blank&quot;&gt;Domain Joined&lt;/a&gt; device posture check to fail, even though the domain matched.&lt;/li&gt;&lt;li&gt;Fixes an issue that prevented logging in to Zscaler Client Connector due to a DNS error caused by incorrect keychain data after upgrading to macOS Tahoe in Strict Enforcement mode.&lt;/li&gt;&lt;li&gt;Fixes an issue that caused the &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-device-posture-profiles#OS-Version&quot; target=&quot;_blank&quot;&gt;OS Version&lt;/a&gt; device posture check to fail for a machine tunnel even though the device was the correct OS version.&lt;/li&gt;&lt;li&gt;Fixes an issue where, after disabling Zscaler Internet Access (ZIA), an old PAC file was restored instead of the one applied by the Jamf Pro deployment when users had Transparent Proxy-based Interception enabled with the Cache System Proxy option enabled.&lt;/li&gt;&lt;li&gt;Fixes a connection delay to Zscaler Private Access (ZPA) that occurred when, after disabling ZPA, a user clicked Turn On if the user had a custom profile for VPN (for Legacy Apps) enabled.&lt;/li&gt;&lt;li&gt;Fixes a connection delay to Zscaler Client Connector that occurred after a device woke up from being idle for a long time or after a restart.&lt;/li&gt;&lt;li&gt;Fixes an issue where, after users clicked Run Zscaler Diagnostics on the More window in the app, the process took a long time to run or became stuck.&lt;/li&gt;&lt;li&gt;Fixes an issue where, if &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/enabling-zpa-device-groups&quot; target=&quot;_blank&quot;&gt;Device Groups&lt;/a&gt; are used for ZPA service entitlement, ZPA wasn&#039;t enabled for a user who logged in to the macOS device after another user logged out.&lt;/li&gt;&lt;li&gt;Fixes an issue where Zscaler Client Connector didn’t accept some DNS query record types (e.g., CNAME), resulting in some domains not being tunneled.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.7.0.126</version>
                                                <pubDate>Mon, 09 Feb 2026 08:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1535385 at https://help.zscaler.com</guid>
            </item>
                    <item>
                <title>Zscaler Client Connector 4.5.0.343 Enhancements and Fixes</title>
                <link>https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026?applicable_category=macOS&amp;applicable_version=4.5.0.343&amp;deployment_date=2026-01-28&amp;id=1535264</link>
                <description>&lt;p class=&quot;note&quot;&gt;This version of Zscaler Client Connector has a known issue where Zscaler Client Connector prematurely switched to the secondary ZPA Public Service Edge for customers using &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/configuring-forwarding-profiles-zscaler-client-connector#forwarding-profile-action-zpa&quot; target=&quot;_blank&quot;&gt;Dynamic ZPA Service Edge Assignment&lt;/a&gt;. This issue has been corrected on Zscaler Client Connector version 4.5.2.175.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Fixes a connection delay to Zscaler Private Access (ZPA) that occurred when, after disabling ZPA, a user clicked Turn On if the user had a custom profile for VPN (for Legacy Apps) enabled.&lt;/li&gt;&lt;li&gt;Fixes an issue where, if &lt;a href=&quot;https://help.zscaler.com/zscaler-client-connector/enabling-zpa-device-groups&quot; target=&quot;_blank&quot;&gt;Device Groups&lt;/a&gt; are used for ZPA service entitlement, ZPA wasn&#039;t enabled for a user who logged in to the macOS device after another user logged out.&lt;/li&gt;&lt;/ul&gt;</description>
                <category>Release Available</category>
                                    <version>4.5.0.343</version>
                                                <pubDate>Wed, 28 Jan 2026 08:00:00 GMT</pubDate>
                <guid isPermaLink="false">feature 1535264 at https://help.zscaler.com</guid>
            </item>
            </channel>
</rss>
