CVE-2026-25684

A file type attribution issue in Zscaler Internet Access File Type Control evaluation rules may allow improper evaluation of File Type Control policies in rare circumstances.

  • Published Sep 18, 2026
  • CVSS 4.4 medium
  • 0.2% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-25684 at the National Vulnerability Database