<rss version="2.0" xml:base="https://trust.zscaler.com/rss-feed/advisories" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>Trust</title>
    <link>https://trust.zscaler.com/rss-feed/advisories</link>
    <description>Trust Post Feeds.</description>
        <generator>trust.zscaler.com</generator>
    <language>en-us</language>
    <atom:link href="https://trust.zscaler.com/rss-feed/advisories" rel="self" type="application/rss+xml"/>
              <item>
        <title>Security Advisory: Linux Kernel Vulnerability (CVE-2026-31431) - zscaler.net, zscalerone.net, zscalertwo.net, zscloud.net, zscalerthree.net, private.zscaler.com, zdxcloud.net, zpatwo.net, app.zsdpc.net, app.eu.zsdpc.net, zpabeta.net, zsdkone.net, zscalerrisk.net, admin.zscaleranalytics.net, zslogin.net</title>
                <link>https://trust.zscaler.com/posts/29306</link>
                                <description>&lt;div id=&quot;post_body_wrapper&quot;&gt;&lt;p&gt;&lt;span&gt;On April 29, 2026, Zscaler was made aware of CVE-2026-31431, a Local Privilege Escalation (LPE) vulnerability affecting Linux kernel versions 4.14 and later. Zscaler has addressed the vulnerability across all its clouds through patching or mitigation.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Zscaler Internet Access (ZIA) distributed products are not impacted. Zscaler suggests adhering to the instructions issued by the operating system vendors for any Linux systems and Zscaler products listed below:&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li data-list-item-id=&quot;ee800d3a7c60af7768f7733fa92d09cd0&quot;&gt;&lt;strong&gt;Zscaler Private Access (ZPA):&lt;/strong&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;a href=&quot;https://help.zscaler.com/zpa/about-connectors&quot;&gt;&lt;span&gt;App Connector&lt;/span&gt;&lt;/a&gt;&lt;span&gt;,&amp;nbsp;&lt;/span&gt;&lt;a href=&quot;https://help.zscaler.com/zpa/about-network-connectors&quot;&gt;&lt;span&gt;Network Connector&lt;/span&gt;&lt;/a&gt;&lt;span&gt;,&amp;nbsp;&lt;/span&gt;&lt;a href=&quot;https://help.zscaler.com/zpa/about-private-service-edges&quot;&gt;&lt;span&gt;Private Service Edge (PSE)&lt;/span&gt;&lt;/a&gt;&lt;span&gt;,&amp;nbsp;&lt;/span&gt;&lt;a href=&quot;https://help.zscaler.com/zpa/about-private-cloud-controllers&quot;&gt;&lt;span&gt;Private Cloud Controller (PCC)&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li data-list-item-id=&quot;efd643c402d5ef0cbc1bbb2716c4ef1e2&quot;&gt;&lt;a href=&quot;https://help.zscaler.com/zero-trust-branch/what-zero-trust-branch&quot;&gt;&lt;span&gt;Zero Trust Branch (ZTB)&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;span&gt;Vendor recommended remediations:&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li data-list-item-id=&quot;e895b1a9b5279b01526956ebe8a79bf36&quot;&gt;&lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2026-31431&quot;&gt;&lt;span&gt;https://nvd.nist.gov/vuln/detail/CVE-2026-31431&lt;/span&gt;&lt;/a&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/li&gt;&lt;li data-list-item-id=&quot;e93a1c5b2c3c5f2a55ce86c1068534c90&quot;&gt;&lt;a href=&quot;https://access.redhat.com/security/cve/cve-2026-31431&quot;&gt;&lt;span&gt;https://access.redhat.com/security/cve/cve-2026-31431&lt;/span&gt;&lt;/a&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/li&gt;&lt;li data-list-item-id=&quot;e3d2f5cde3c842fda81f3d15f64180c77&quot;&gt;&lt;a href=&quot;https://security-tracker.debian.org/tracker/CVE-2026-31431&quot;&gt;&lt;span&gt;https://security-tracker.debian.org/tracker/CVE-2026-31431&lt;/span&gt;&lt;/a&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/li&gt;&lt;li data-list-item-id=&quot;ef78bf2953bbd95d1b44772c609f23096&quot;&gt;&lt;a href=&quot;https://ubuntu.com/security/CVE-2026-31431&quot;&gt;&lt;span&gt;https://ubuntu.com/security/CVE-2026-31431&lt;/span&gt;&lt;/a&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/li&gt;&lt;li data-list-item-id=&quot;ec4e7ab47c7cdda7907915e0c1fb2d936&quot;&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-31431.html&quot;&gt;&lt;span&gt;https://www.suse.com/security/cve/CVE-2026-31431.html&lt;/span&gt;&lt;/a&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description>
                <pubDate>Fri, 01 May 2026 00:00:00 GMT</pubDate>
                                                                          <ResolvedDate>Fri, 01 May 2026 04:44:03 GMT</ResolvedDate>
                          <eventType>No Service Impact</eventType>
                                                          <HowFound>Internal Monitoring</HowFound>
                                                        <guid isPermaLink="false">29306 at https://trust.zscaler.com</guid>
        <category domain="https://trust.zscaler.com">Advisory</category>
      </item>
          <item>
        <title>Cellular Portal Migration to Experience Center - zscaler.net, zscalerone.net, zscalertwo.net, zscloud.net, zscalerthree.net, private.zscaler.com, zdxcloud.net, zpatwo.net, zslogin.net</title>
                <link>https://trust.zscaler.com/posts/29261</link>
                                <description>&lt;div id=&quot;post_body_wrapper&quot;&gt;&lt;p&gt;&lt;strong&gt;Zscaler Cellular Portal is Being disabled—Move to Experience Center by May 15, 2026&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;What is changing?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Effective May 15, 2026, Zscaler is disabling the Zscaler Cellular Portal at&lt;/span&gt;&lt;a href=&quot;https://admin.ztsim.com/&quot;&gt;&lt;span&gt;&amp;nbsp;https://admin.ztsim.com&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. After this date, the Zscaler Cellular Portal will no longer be available for&amp;nbsp;managing or monitoring Zscaler Cellular services.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;To continue administering and gaining visibility into Zscaler Cellular services, customers must use&amp;nbsp;Zscaler Experience Center at&amp;nbsp;&lt;/span&gt;&lt;a href=&quot;https://console.zscaler.com/&quot;&gt;&lt;span&gt;https://console.zscaler.com&lt;/span&gt;&lt;/a&gt;&lt;span&gt;—Zscaler’s centralized administrative and insights platform.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Who is impacted?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;All customers currently using the Zscaler Cellular Portal for configuration, operations, monitoring, or troubleshooting of Zscaler Cellular services.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Key information&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li data-list-item-id=&quot;e574cdaa093bfce358bab22a1faa83e67&quot;&gt;&lt;span&gt;Zscaler Cellular Portal disablement date:&amp;nbsp;May 15, 2026.&lt;/span&gt;&lt;/li&gt;&lt;li data-list-item-id=&quot;e5786fb324c296b34531f0cfe93aabf43&quot;&gt;&lt;span&gt;Management and monitoring in one place: Use the Experience Center to&amp;nbsp;configure, manage, and monitor Zscaler Cellular services.&lt;/span&gt;&lt;/li&gt;&lt;li data-list-item-id=&quot;ec54cb34a98a41a98b082706908931dd1&quot;&gt;&lt;p&gt;&lt;span&gt;Avoid operational disruption: Ensure your teams transition workflows and access&amp;nbsp;before May 15, 2026, to prevent loss of administrative access and visibility.&lt;/span&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Next steps&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li data-list-item-id=&quot;e0d3cff673b1a24622328a218a9df3f79&quot;&gt;&lt;span&gt;Start using Experience Center: Log in to&amp;nbsp;&lt;/span&gt;&lt;a href=&quot;https://console.zscaler.com/&quot;&gt;&lt;span&gt;https://console.zscaler.com&lt;/span&gt;&lt;/a&gt;&lt;span&gt; and validate your access to the Zscaler Cellular experience needed for your role.&lt;/span&gt;&lt;/li&gt;&lt;li data-list-item-id=&quot;e70243de2e6fdf2f1db97930373d80735&quot;&gt;&lt;span&gt;Transition operational workflows: Update runbooks, bookmarks, and internal documentation to point to Experience Center for Zscaler Cellular management and monitoring.&lt;/span&gt;&lt;/li&gt;&lt;li data-list-item-id=&quot;e3ba02007e9aeac987f531eca0f531040&quot;&gt;&lt;span&gt;Engage your Zscaler Account team: Your Account Team or Technical Success Manager can help confirm readiness, access, and best practices for the move.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;What if I have more questions?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Contact&amp;nbsp;Zscaler Support using the Support link in the Zscaler help portals, or call:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;+1 (408) 752-5885&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;+1 (844) 971-0010 (U.S.)&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li data-list-item-id=&quot;ec3e4797ad331326ac03cbaa32eced67d&quot;&gt;&lt;span&gt;Update 4/30: Title Change&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description>
                <pubDate>Thu, 30 Apr 2026 00:00:00 GMT</pubDate>
                                                                                  <eventType>Informational</eventType>
                                                                                                <guid isPermaLink="false">29261 at https://trust.zscaler.com</guid>
        <category domain="https://trust.zscaler.com">Advisory</category>
      </item>
          <item>
        <title>Operational Resilience Update: Managing Subsea Cable Risk in the Persian Gulf and Beyond - zscaler.net, zscalerone.net, zscalertwo.net, zscloud.net, zscalerthree.net, private.zscaler.com, zdxcloud.net, zpatwo.net, app.zsdpc.net, app.eu.zsdpc.net, zpabeta.net, zsdkone.net, zscalerrisk.net, admin.zscaleranalytics.net, zslogin.net</title>
                <link>https://trust.zscaler.com/posts/29186</link>
                                <description>&lt;div&gt;Current geopolitical conditions have elevated the risk of potential disruptions to subsea cable infrastructure in the Persian Gulf region.&lt;br&gt;If such events occur, we would expect the primary impact to be localized within the Gulf, including countries such as Iran, Iraq, Qatar, Kuwait, and to a lesser extent the UAE and Saudi Arabia. The most likely effect would be reduced capacity or constrained routing options, which may result in localized performance degradation rather than widespread outages.&lt;br&gt;For traffic between India and Europe, the majority of primary connectivity paths traverse the Gulf of Aden and Red Sea corridor. As a result, activity in the Persian Gulf region alone is not expected to materially impact these routes.&lt;br&gt;Following earlier incidents in the Red Sea, we have implemented enhanced monitoring across key paths between India, Europe, and the United States. This allows us to rapidly detect anomalies and take action where possible.&lt;br&gt;Our architecture is designed with resilience in mind:&lt;br&gt;&amp;nbsp;&lt;/div&gt;&lt;ul&gt;&lt;li data-list-item-id=&quot;edc3cf2eb4938034eddc57bf3abf5455e&quot;&gt;We maintain carrier diversity and can dynamically route traffic across multiple providers&lt;/li&gt;&lt;li data-list-item-id=&quot;e66ee92f8376c91ef7a2aa9ae57741cbf&quot;&gt;We partner closely with leading hyperscalers to engineer traffic paths where feasible&lt;/li&gt;&lt;li data-list-item-id=&quot;e8ee5ed32a351e1fd9c63f20800e16a96&quot;&gt;Our engineering teams have pre-tested mitigation strategies to respond to large-scale network events&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;When disruptions occur, our teams actively work to minimize impact by leveraging available routing, partner, provider, and architectural options.&lt;br&gt;While the precise impact of any given event depends on its scope and severity, please be assured that we are actively monitoring the situation and are prepared to respond quickly to protect service continuity.&lt;/div&gt;</description>
                <pubDate>Thu, 23 Apr 2026 00:00:00 GMT</pubDate>
                                                                                  <eventType>Informational</eventType>
                                                                                                <guid isPermaLink="false">29186 at https://trust.zscaler.com</guid>
        <category domain="https://trust.zscaler.com">Advisory</category>
      </item>
          <item>
        <title>Migration Notice: VPN (for Legacy Apps) - Upgrading VPN Service Edge/Network Connector - private.zscaler.com, zpatwo.net, zpabeta.net</title>
                <link>https://trust.zscaler.com/posts/29176</link>
                                <description>&lt;div id=&quot;post_body_wrapper&quot;&gt;&lt;p&gt;&lt;span&gt;Upgrading VPN Service Edge/Network Connector from Previous Generation to Next Generation with BGP Support&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;As part of Zscaler’s ongoing efforts to standardize and modernize its public cloud infrastructure, customers currently using the previous generation VPN Service Edge and Network Connectors are required to migrate to the next generation VPN Service Edge with BGP support, along with Network Connectors that support BGP.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;The next generation VPN Service Edge and Network Connectors offer enhanced scalability, improved resiliency, and dynamic routing capabilities through BGP.&lt;/span&gt;&lt;br&gt;&lt;br&gt;&lt;strong&gt;What’s Changing:&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;All customers using the previous generation VPN Service Edge and Network Connectors must complete their migration to the next generation VPN Service Edge and Network Connectors with BGP support by&amp;nbsp;&lt;/span&gt;&lt;strong&gt;July 31, 2026&lt;/strong&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;After this date, the previous generation VPN Service Edge and Network Connectors will no longer be supported.&lt;/span&gt;&lt;br&gt;&lt;br&gt;&lt;strong&gt;Who is Impacted:&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;This applies only to customers currently using the previous generation VPN Service Edge and Network Connectors.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Customers already deployed on the next generation VPN Service Edge (BGP-enabled) and Network Connectors are not impacted.&lt;/span&gt;&lt;br&gt;&lt;br&gt;&lt;strong&gt;How can you verify whether you are impacted by this? &lt;/strong&gt;&lt;a href=&quot;https://help.zscaler.com/zpa/replacing-or-migrating-network-connectors-support-redundancy&quot;&gt;&lt;strong&gt;Learn More&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;Navigate to the VPN Service Edge configuration page&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;Confirm that BGP Local Router ID is enabled&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Confirm that Redundant Mode is enabled&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;If both settings are enabled, you are not impacted by this migration associated with the advisory&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Navigate to the Network Connector configuration &amp;gt; Click on edit&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;Confirm that BGP Local Router ID is enabled&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Navigate to the Network Connector Group configuration&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;Confirm that Redundant Mode is enabled by expanding the group.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;If both settings are enabled, you are not impacted by this migration associated with the advisory&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Migration Steps:&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Here’s the public documentation outlining all the steps in the correct sequence: &lt;/span&gt;&lt;a href=&quot;https://help.zscaler.com/zpa/replacing-or-migrating-network-connectors-redundancy-capable-network-connectors&quot;&gt;&lt;strong&gt;Replacing or Migrating Existing Network Connectors with Network Connectors that Support Redundancy&lt;/strong&gt;&lt;/a&gt;&lt;br&gt;&lt;br&gt;Regarding BGP, peering between the Network Connectors and VPN Service Edges is automatically established &lt;strong&gt;(Managed by Zscaler)&lt;/strong&gt;. Once firewall whitelisting is configured for UDP ports 51820–53000 on the perimeter firewall, BGP will automatically establish between the Network Connectors and the VPN Service Edges.&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;br&gt;&lt;br&gt;&lt;span&gt;On the customer side (Layer 3 router, switch, or firewall device to Network Connectors), BGP is recommended but &lt;strong&gt;optional&lt;/strong&gt;. If the customer chooses not to use BGP, they can continue using &lt;strong&gt;static routing&lt;/strong&gt; by configuring routes that point to multiple Network Connectors as the next hop.&lt;/span&gt;&lt;/p&gt;&lt;div&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;When using static routing, “Advertise LAN Segments Locally” in the Network Connector group must be enabled.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;When using BGP between a Layer 3 router, switch, or firewall device and the Network Connectors, you must disable “Advertise LAN Segments Locally” in the Network Connector group.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;p&gt;&lt;strong&gt;Note&lt;/strong&gt;&lt;span&gt;:&amp;nbsp;&lt;/span&gt;&lt;strong&gt;After the migration is successfully completed and all functionality is&amp;nbsp;verified, the previous generation VPN Service Edge and Network Connector must be decommissioned to fully complete the transition.&lt;/strong&gt;&lt;br&gt;&lt;br&gt;&lt;strong&gt;Required Action:&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Please plan and complete the migration during a scheduled maintenance window.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Important:&lt;/strong&gt;&lt;span&gt; Make sure that redundancy is enabled in the tenant -&amp;nbsp;&lt;/span&gt;&lt;strong&gt;Contact Zscaler Support&lt;/strong&gt;&lt;span&gt; or your&amp;nbsp;&lt;/span&gt;&lt;strong&gt;Zscaler Account team&lt;/strong&gt;&lt;span&gt; and make sure that the VPN (for Legacy Apps) redundancy flag is enabled.&lt;/span&gt;&lt;br&gt;&lt;br&gt;&lt;strong&gt;Outcome:&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;After migration, traffic will be routed through the new BGP-enabled VPN Service Edge and Network Connectors, delivering:&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;Improved Resiliency&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Dynamic routing&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Improved scalability&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Standardized cloud architecture&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description>
                <pubDate>Wed, 22 Apr 2026 00:00:00 GMT</pubDate>
                                                                                  <eventType>Informational</eventType>
                                                                                                <guid isPermaLink="false">29176 at https://trust.zscaler.com</guid>
        <category domain="https://trust.zscaler.com">Advisory</category>
      </item>
          <item>
        <title>Zscaler Client Connector for VDI Deployment Issue - zscaler.net, zscalerone.net, zscalertwo.net, zscloud.net, zscalerthree.net, private.zscaler.com, zdxcloud.net, zpatwo.net, zslogin.net</title>
                <link>https://trust.zscaler.com/posts/29121</link>
                                <description>&lt;div id=&quot;post_body_wrapper_main&quot;&gt;&lt;div id=&quot;post_body_wrapper&quot;&gt;&lt;p class=&quot;post_body&quot; id=&quot;post_body&quot;&gt;Zscaler detected an issue where the existing access token that was generated before April 11 can not be used to deploy Zscaler Client Connector. As a workaround customers can create a new access token while the Zscaler team investigates and fixes the issue.&amp;nbsp;&lt;br&gt;&lt;br&gt;&lt;strong&gt;Affected Services: &lt;/strong&gt;&lt;span&gt;Zscaler Client Connector for VDI&lt;/span&gt;&lt;br&gt;&lt;br&gt;&lt;strong&gt;Workaround:&amp;nbsp;&lt;/strong&gt;&lt;br&gt;- Generate a new access token from the Cloud and Branch Connector portal (Administration &amp;gt; VDI Templates) and use the new token for any new deployments&lt;br&gt;- For non-persistent VDI where no users backup/restore &amp;nbsp;was implemented: Update the golden/master image with the new access token, this is critical since the agent re-enrolls on every boot.&lt;br&gt;&lt;br&gt;&lt;strong&gt;Root Cause:&lt;/strong&gt;&lt;span&gt;&amp;nbsp;Central Authority (CA) certificate update caused this issue.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;</description>
                <pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate>
                                                                                  <eventType>Informational</eventType>
                                  <customerImpact>- Customers won’t be able to deploy Zscaler Client Connector for VDI using existing access tokens that were created before April 11 (administrators generate access tokens in the Cloud and Branch Connector portal under Administration &gt; VDI Templates). Administrators will receive &quot;Init Config error&quot; once they try to deploy Zscaler Client Connector for VDI with an existing access token. 


- Customers running non-persistent VDI deployments and do not have a backup restore mechanism implemented to restore user profiles and config files stored in %programdata%/ZCCVDI. In this case, the agent must re-enroll on every boot using the access token from the golden image. If the golden image contains an access token generated before April 11, every boot will fail with &quot;Init Config error&quot; until the golden image is updated with a new token. Already-enrolled agents in persistent environments are not affected, as they do not need to re-enroll.</customerImpact>
                                                                                <guid isPermaLink="false">29121 at https://trust.zscaler.com</guid>
        <category domain="https://trust.zscaler.com">Advisory</category>
      </item>
          <item>
        <title>UI Node will stop supporting Public API Traffic - zscaler.net, zscalerone.net, zscalertwo.net, zscloud.net, zscalerthree.net</title>
                <link>https://trust.zscaler.com/posts/29096</link>
                                <description>&lt;p&gt;&lt;span&gt;Zscaler is announcing the official retirement of UI nodes for servicing Public API traffic. Currently, some Public API traffic lands on UI nodes instead of the designated Zscaler API (ZSAPI) nodes.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;To ensure optimal performance and alignment with our architectural standards,&amp;nbsp;&lt;/span&gt;&lt;strong&gt;UI nodes will stop servicing Public API calls starting September 01, 2026&lt;/strong&gt;&lt;span&gt;. This follows the initial announcement of the ZSAPI framework transition made in April 2021 under the section&amp;nbsp;&lt;/span&gt;&lt;a href=&quot;https://help.zscaler.com/zia/release-upgrade-summary-2021?applicable_category=zscaler.net&amp;amp;deployment_date=2021-04-16&amp;amp;id=1377151&quot;&gt;&lt;span&gt;Updates to Cloud Service API&lt;/span&gt;&lt;/a&gt;&lt;em&gt;.&lt;/em&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Customer Impact&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Any automation scripts, programs, or third-party integrations currently sending Public API traffic to UI nodes (`admin.&amp;lt;Zscaler Cloud Name&amp;gt;`) will no longer be supported after September 01, 2026.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Customers who have already transitioned to ZSAPI or OneAPI frameworks are not impacted.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Customer Guidance &amp;amp; Action Required&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;To avoid service disruption, all necessary changes must be completed by&amp;nbsp;&lt;/span&gt;&lt;strong&gt;August 31, 2026&lt;/strong&gt;&lt;span&gt;. Customers have two options to mitigate this risk:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Option 1: Transition to OneAPI Framework (Recommended)&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Zscaler recommends transitioning to the OneAPI framework, our new and unified automation framework for all Zscaler products.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li data-list-item-id=&quot;e78239e3aa79b10efd8d318ef237f9d9a&quot;&gt;&lt;strong&gt;Endpoint&lt;/strong&gt;&lt;span&gt;:&lt;/span&gt;&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;&lt;span&gt;`https://api.zsapi.net`&lt;/span&gt;&lt;/li&gt;&lt;li data-list-item-id=&quot;e1d7b0d7ee1b5c217a42b658b9926558f&quot;&gt;&lt;strong&gt;Getting Started&lt;/strong&gt;&lt;span&gt;:&lt;/span&gt;&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;&lt;span&gt;Refer to the&amp;nbsp;&lt;/span&gt;&lt;a href=&quot;https://automate.zscaler.com/docs/getting-started/getting-started&quot;&gt;&lt;span&gt;Zscaler OneAPI documentation&lt;/span&gt;&lt;/a&gt;&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;&lt;span&gt;for migration guides and developer resources.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Option 2: Transition to ZSAPI Nodes (Legacy Framework)&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Update your existing automation scripts or code to point to ZSAPI nodes instead of UI nodes.&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li data-list-item-id=&quot;e6d17b82a5517dfd05dd1ccadc3230043&quot;&gt;&lt;strong&gt;&amp;nbsp;Identify&lt;/strong&gt;&lt;span&gt;:&lt;/span&gt;&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;&lt;span&gt;Locate instances using `https://admin.&amp;lt;Zscaler Cloud Name&amp;gt;` for API calls.&lt;/span&gt;&lt;/li&gt;&lt;li data-list-item-id=&quot;e2267a039e667f181fe8dadfd581bb8f5&quot;&gt;&lt;strong&gt;&amp;nbsp;Replace&lt;/strong&gt;&lt;span&gt;:&lt;/span&gt;&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;&lt;span&gt;Update the endpoint to `https://zsapi.&amp;lt;Zscaler Cloud Name&amp;gt;`.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Zscaler Partner Integrations Impact&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;If you are using any&amp;nbsp;&lt;/span&gt;&lt;a href=&quot;https://help.zscaler.com/zscaler-technology-partners&quot;&gt;&lt;span&gt;Zscaler Partner Integrations&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, refer to the official guides on how to update the endpoint API using Option 2 above.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Timeline&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li data-list-item-id=&quot;e676cf8beafcdd5c4b598ef669291871f&quot;&gt;&lt;strong&gt;Initial Announcement&lt;/strong&gt;&lt;span&gt;:&lt;/span&gt;&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;&lt;span&gt;April 2021&lt;/span&gt;&lt;/li&gt;&lt;li data-list-item-id=&quot;e8dbe3150ba8a63ecbad16d9f5fdff5f5&quot;&gt;&lt;strong&gt;Deadline for Customer Action&lt;/strong&gt;&lt;span&gt;:&lt;/span&gt;&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;&lt;span&gt;August 31, 2026&lt;/span&gt;&lt;/li&gt;&lt;li data-list-item-id=&quot;e7f1f7c9b7f4a339916d8f2a22e3d4b41&quot;&gt;&lt;strong&gt;Retirement Date (End of Service)&lt;/strong&gt;&lt;span&gt;:&lt;/span&gt;&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;&lt;span&gt;September 01, 2026&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;What if I have more questions?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;If you have additional questions, contact your Technical Success Manager or Zscaler Support via the Support link in the Zscaler Internet Access or ZIdentity Admin Portal, or call us at +1 (408) 752-5885. Within the U.S., you can use +1 (844) 971-0010&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li data-list-item-id=&quot;eaf0cd3f8b65bd4399b164162190bd33e&quot;&gt;&lt;span&gt;Update 4/27: Verbiage update&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;</description>
                <pubDate>Thu, 16 Apr 2026 00:00:00 GMT</pubDate>
                                                                                  <eventType>Informational</eventType>
                                                                                                <guid isPermaLink="false">29096 at https://trust.zscaler.com</guid>
        <category domain="https://trust.zscaler.com">Advisory</category>
      </item>
          <item>
        <title>Performance Degradation Impacting Case Creation - zscaler.net, zscalerone.net, zscalertwo.net, zscloud.net, zscalerthree.net, private.zscaler.com, zdxcloud.net, zpatwo.net, app.zsdpc.net, app.eu.zsdpc.net, zpabeta.net, zsdkone.net, zscalerrisk.net, admin.zscaleranalytics.net, zslogin.net</title>
                <link>https://trust.zscaler.com/posts/29021</link>
                                <description>&lt;div id=&quot;post_body_wrapper_main&quot;&gt;&lt;p&gt;Zscaler is currently aware of a performance degradation affecting case creation, associated with a third-party service provider. At this time, core Zscaler services, including the data plane and control plane, continue to operate normally. We are actively collaborating with the impacted service provider, who has acknowledged the issue within their managed infrastructure and is working toward resolution. The service provider has identified the underlying cause and initiated remediation actions. Based on current guidance, full restoration is expected to take several hours.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Customer Impact:&amp;nbsp;&lt;/strong&gt;&lt;span&gt;Affected customers may experience elevated response times when creating or updating records via the user interface or through integrations. In high-volume scenarios, this may also result in intermittent errors during transaction processing, including workflows such as case creation, live chat interactions, and automated flows.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Workaround:&amp;nbsp;&lt;/strong&gt;&lt;span&gt;Customers requiring immediate assistance are advised to contact Zscaler Support via phone for expedited handling.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Zscaler is actively collaborating with the service provider and will continue to provide updates as more information becomes available.&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;latest-update&quot;&gt;&lt;p class=&quot;zs-update&quot;&gt;&lt;strong&gt;Latest Update - &lt;/strong&gt;&lt;span class=&quot;report-time&quot;&gt;Tue, 14 Apr 2026 22:00:57 UTC&lt;/span&gt;&lt;/p&gt;&lt;p&gt;The issue impacting case creation has been resolved. The service provider has implemented the fix and confirmed that services have been restored. Zscaler will continue to monitor the environment in collaboration with the service provider to ensure ongoing stability.&lt;/p&gt;&lt;/div&gt;&lt;div class=&quot;post-updates&quot; id=&quot;post-updates&quot;&gt;&lt;div class=&quot;update-list update-2&quot;&gt;&lt;p class=&quot;zs-update&quot;&gt;Update - &lt;span class=&quot;report-time&quot;&gt;Tue, 14 Apr 2026 22:00:57 UTC&lt;/span&gt;&lt;/p&gt;&lt;p&gt;The issue impacting case creation has been resolved. The service provider has implemented the fix and confirmed that services have been restored. Zscaler will continue to monitor the environment in collaboration with the service provider to ensure ongoing stability.&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
                <pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate>
                                                                          <ResolvedDate>Tue, 14 Apr 2026 22:02:24 GMT</ResolvedDate>
                          <eventType>Informational</eventType>
                                                                                                <guid isPermaLink="false">29021 at https://trust.zscaler.com</guid>
        <category domain="https://trust.zscaler.com">Advisory</category>
      </item>
          <item>
        <title>Delay in Processing Inbound Emails to Support Cases - zscaler.net, zscalerone.net, zscalertwo.net, zscloud.net, zscalerthree.net, private.zscaler.com, zdxcloud.net, zpatwo.net, app.zsdpc.net, app.eu.zsdpc.net, zpabeta.net, zsdkone.net, zscalerrisk.net, admin.zscaleranalytics.net, zslogin.net</title>
                <link>https://trust.zscaler.com/posts/28896</link>
                                <description>&lt;div id=&quot;post_body_wrapper_main&quot;&gt;&lt;p&gt;&lt;span&gt;Zscaler is aware of an issue impacting delay in processing inbound emails to support cases.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Zscaler services are operating normally; delays are currently impacting the synchronization of inbound email communications related to support cases. This is due to a dependency issue with our service provider that is affecting email processing, leading to slower updates. Zscaler is actively coordinating with the service provider to restore normal functionality.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Impact:&amp;nbsp;&lt;/strong&gt;&lt;span&gt;During this time, customers may experience delays in email updates, including slower responses or delayed synchronization of messages within existing or new support cases.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Workaround:&lt;/strong&gt;&lt;span&gt; Customers needing urgent assistance should contact Zscaler Support by phone or update their case directly through the Customer Support Portal.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Zscaler will continue to provide updates as more information becomes available and service is restored.&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;post-updates&quot; id=&quot;post-updates&quot;&gt;&lt;div class=&quot;update-list update-1&quot;&gt;&lt;p class=&quot;zs-update&quot;&gt;Update - &lt;span class=&quot;report-time&quot;&gt;Wed, 08 Apr 2026 22:51:51 UTC&lt;/span&gt;&lt;/p&gt;&lt;p&gt;Zscaler has received confirmation that the issue has been addressed and a fix has been implemented by the service provider. Emails that were temporarily delayed have been automatically retried and are now being processed. The service provider is continuing to monitor stability, and Zscaler is actively monitoring the environment to ensure sustained recovery.&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
                <pubDate>Wed, 08 Apr 2026 00:00:00 GMT</pubDate>
                                                                          <ResolvedDate>Wed, 08 Apr 2026 22:52:29 GMT</ResolvedDate>
                          <eventType>Informational</eventType>
                                                                                                <guid isPermaLink="false">28896 at https://trust.zscaler.com</guid>
        <category domain="https://trust.zscaler.com">Advisory</category>
      </item>
          <item>
        <title>Axios Supply Chain Attack Update - zscaler.net, zscalerone.net, zscalertwo.net, zscloud.net, zscalerthree.net, private.zscaler.com, zdxcloud.net, zpatwo.net, app.zsdpc.net, app.eu.zsdpc.net, zpabeta.net, zsdkone.net, zscalerrisk.net, admin.zscaleranalytics.net, zslogin.net</title>
                <link>https://trust.zscaler.com/posts/28816</link>
                                <description>&lt;p&gt;&lt;span&gt;Zscaler has analyzed the supply chain compromises affecting the Axios npm packages.&amp;nbsp;&lt;/span&gt;&lt;strong&gt;Analysis confirms no impact to Zscaler platforms, products, or internal systems&lt;/strong&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;As a best practice, customers should review their environments for the following impacted versions:&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Axios npm package versions:&lt;span&gt; 1.14.1 and 0.30.4&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;span&gt;Actions if you have an impacted version:&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Update/Revert:&amp;nbsp;&lt;span&gt;Revert or pin Axios to known safe versions (e.g., 1.14.0 or 0.30.3)&lt;/span&gt;&lt;/li&gt;&lt;li&gt;Rotate Credentials:&amp;nbsp;&lt;span&gt;Update all API keys, cloud tokens, and environment variables associated with this library.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;span&gt;Zscaler will continue to monitor the situation and update this post if new information emerges.&lt;/span&gt;&lt;/p&gt;</description>
                <pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate>
                                                                          <ResolvedDate>Fri, 03 Apr 2026 17:12:19 GMT</ResolvedDate>
                          <eventType>Informational</eventType>
                                                          <HowFound>Internal Monitoring</HowFound>
                                                        <guid isPermaLink="false">28816 at https://trust.zscaler.com</guid>
        <category domain="https://trust.zscaler.com">Advisory</category>
      </item>
          <item>
        <title>Action Required — Verify/Correct Your Z-Identity IdP “Primary Email” Attribute Mapping  - zscaler.net, zscalerone.net, zscalertwo.net, zscloud.net, zscalerthree.net, private.zscaler.com, zdxcloud.net, zpatwo.net, app.zsdpc.net, app.eu.zsdpc.net, zpabeta.net, zsdkone.net, zscalerrisk.net, admin.zscaleranalytics.net, zslogin.net</title>
                <link>https://trust.zscaler.com/posts/28776</link>
                                <description>&lt;p&gt;&lt;span&gt;Zscaler is proactively reaching out to help prevent potential login failures to the&amp;nbsp;Z-Identity Admin Console when authenticating through your&amp;nbsp;Identity Provider (IdP). Based on monitoring, your tenant may be&amp;nbsp;missing or mis-mapping the required&amp;nbsp;Primary Email attribute used during&amp;nbsp;JIT (Just-In-Time) provisioning.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;This advisory relates to the recent incident and follow-up corrective actions (Reference: Trust Post:&amp;nbsp;&lt;/span&gt;&lt;a href=&quot;https://trust.zscaler.com/zslogin.net/posts/28626&quot;&gt;&lt;em&gt;Z-Identity Portal Issue&lt;/em&gt;&lt;/a&gt;&lt;span&gt;).&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;What is the issue?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;On&amp;nbsp;Mar 21st, some customers experienced login failures to the Z-Identity Admin Console when authenticating via their IdP. The error observed was:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;“Invalid Input Error: Primary Email is required.”&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Why this is needed&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Zscaler deployed an update to improve validation of attributes during&amp;nbsp;JIT provisioning. A subset of customers encountered login failures where the IdP was&amp;nbsp;not sending the required email attribute or it was&amp;nbsp;incorrectly mapped. To restore stability, Zscaler&amp;nbsp;reverted the change.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Zscaler is now running a&amp;nbsp;monitoring-only period and asking customers to validate/correct mappings&amp;nbsp;before the improved validation is re-enabled in a controlled manner.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Who is impacted?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;You may be impacted if all of the following apply:&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;IdP-based authentication is enabled (SSO via Google Workspace, Azure AD, Okta, etc.)&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;JIT provisioning is enabled&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;The&amp;nbsp;Primary Email attribute mapping is&amp;nbsp;missing or incorrect (wrong attribute name or not present in the IDP assertion)&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;span&gt;Why JIT matters: JIT synchronizes user attributes from the IdP to Z-Identity at login; missing/incorrect Primary Email mapping is most likely to cause failures when validation is re-enabled.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Action Required — Verify your IdP “Primary Email” attribute mapping&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Quick verification steps&lt;/span&gt;&lt;/p&gt;&lt;ol&gt;&lt;li&gt;&lt;span&gt;Confirm IDP assertion includes an email address&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;In your IdP admin console, open the&amp;nbsp;Zscaler Z-Identity IDP app configuration.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Use&amp;nbsp;Test / Preview IDP Response.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Verify an&amp;nbsp;email attribute is present and contains the user’s email address.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Confirm attribute/claim mapping matches the assertion&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;Review your IdP attribute/claim mappings.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Ensure the mapped attribute name matches the actual attribute name in the assertion.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Recommended: Test with JIT provisioning&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;Create a&amp;nbsp;new test user in the IdP that does&amp;nbsp;not exist in Z-Identity.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Attempt login to the&amp;nbsp;Z-Identity Admin Console via IdP.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Expected results:&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;If the user is created successfully → mapping is correct.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;If you see&amp;nbsp;“Primary Email is required” → mapping needs correction.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&lt;span&gt;If your test fails (remediation)&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;Update the IdP mapping to use the&amp;nbsp;correct email attribute name&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Ensure the email attribute is included in the IDP assertion&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Re-test using a&amp;nbsp;new JIT user&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Notify your&amp;nbsp;TSM/Zscaler Support once corrected&amp;nbsp;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Timeline / next steps&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Zscaler plans to re-enable the updated validation in approximately&amp;nbsp;three weeks. Customers are requested to remediate&amp;nbsp;before April 15th to ensure adequate time for correction and testing.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Support / escalation&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;If you need help validating the IDP assertion or correcting the mapping, contact&amp;nbsp;Zscaler Support and include:&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;Your&amp;nbsp;IdP vendor/type&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Screenshot/description of your&amp;nbsp;email attribute/claim mapping&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;(If available) the&amp;nbsp;attribute name used for email in the IDP assertion (no sensitive data required)&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;</description>
                <pubDate>Tue, 31 Mar 2026 00:00:00 GMT</pubDate>
                                                                                  <eventType>Under Investigation</eventType>
                                                          <HowFound>Internal Monitoring</HowFound>
                                                        <guid isPermaLink="false">28776 at https://trust.zscaler.com</guid>
        <category domain="https://trust.zscaler.com">Advisory</category>
      </item>
          <item>
        <title>Experience Center – SSO Error When Accessing Support Tab - zslogin.net</title>
                <link>https://trust.zscaler.com/posts/28726</link>
                                <description>&lt;div id=&quot;post_body_wrapper_main&quot;&gt;&lt;div id=&quot;post_body_wrapper_main&quot;&gt;&lt;div id=&quot;post_body_wrapper&quot;&gt;&lt;p&gt;&lt;span&gt;Zscaler is investigating an issue impacting Experience Center customers, where users may encounter an SSO error when navigating to the Support tab within the Experience Portal.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Impact: &lt;/strong&gt;&lt;span&gt;Customers attempting to access the Support tab through the Experience Center portal may be unable to successfully authenticate via SSO. All other platform functionalities remain unaffected.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Workaround:&lt;/strong&gt;&lt;br&gt;&lt;span&gt;Customers can continue to access the Support Portal using the following validated workaround:&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;Log in to an alternate Zscaler Product Admin Portal (e.g., ZIA, ZPA, or ZDX)&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Navigate to the Support Portal from that product interface&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;From there:&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;View existing cases across all products, including Experience Center, or&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Create a new case and manually select:&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Product:&lt;/strong&gt;&lt;span&gt; Experience Center&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Company ID:&lt;/strong&gt;&lt;span&gt; Corresponding Experience Center tenant&amp;nbsp;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;span&gt;Zscaler has identified the underlying cause of the issue and a fix has been developed. Deployment of the fix is currently planned for&amp;nbsp;&lt;/span&gt;&lt;strong&gt;March 28, 2026, &lt;/strong&gt;during the&lt;strong&gt; &lt;/strong&gt;&lt;a href=&quot;https://trust.zscaler.com/zslogin.net/maintenance&quot;&gt;&lt;strong&gt;Maintenance Window&lt;/strong&gt;&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;Update - &lt;span class=&quot;report-time&quot;&gt;Sat, 28 Mar 2026 09:59:05 UTC&lt;/span&gt;&lt;/p&gt;&lt;p&gt;Zscaler has deployed a fix, and the issue impacting access to the Support tab in the Experience Center portal has been resolved. Services have been restored, and customers should now be able to access Support functionality normally. Zscaler will continue to monitor the environment to ensure ongoing stability.&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
                <pubDate>Fri, 27 Mar 2026 00:00:00 GMT</pubDate>
                                                                          <ResolvedDate>Sat, 28 Mar 2026 10:00:06 GMT</ResolvedDate>
                          <eventType>Informational</eventType>
                                                                                                <guid isPermaLink="false">28726 at https://trust.zscaler.com</guid>
        <category domain="https://trust.zscaler.com">Advisory</category>
      </item>
          <item>
        <title>Trivy and LiteLLM Supply Chain Incident (CVE-2026-33634) Update - zscaler.net, zscalerone.net, zscalertwo.net, zscloud.net, zscalerthree.net, private.zscaler.com, zdxcloud.net, zpatwo.net, app.zsdpc.net, app.eu.zsdpc.net, zpabeta.net, zsdkone.net, zscalerrisk.net, admin.zscaleranalytics.net, zslogin.net</title>
                <link>https://trust.zscaler.com/posts/28696</link>
                                <description>&lt;div id=&quot;post_body_wrapper&quot;&gt;&lt;p&gt;&lt;span&gt;Zscaler has analyzed the supply chain compromises affecting the Trivy security scanner and LiteLLM.&amp;nbsp;&lt;/span&gt;&lt;strong&gt;Analysis confirms no impact to Zscaler platforms, products, or internal systems, including AI Guard&lt;/strong&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;As a best practice customers should review their environments for the following impacted versions:&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Trivy:&lt;/strong&gt;&lt;span&gt; Container images&amp;nbsp;v0.69.5–v0.69.6&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;LiteLLM:&amp;nbsp;&lt;/strong&gt;&lt;span&gt;Versions&amp;nbsp;1.82.7 and&amp;nbsp;1.82.8.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;span&gt;Actions if you have an impacted version:&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Update/Revert:&amp;nbsp;&lt;/strong&gt;&lt;span&gt;Upgrade Trivy to&amp;nbsp;v0.69.7 or later and downgrade LiteLLM to&amp;nbsp;v1.82.6.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Rotate Credentials:&amp;nbsp;&lt;/strong&gt;&lt;span&gt;Update all API keys, cloud tokens, and environment variables associated with these tools.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;span&gt;Zscaler will continue to monitor the situation and update this post if new information emerges.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</description>
                <pubDate>Fri, 27 Mar 2026 00:00:00 GMT</pubDate>
                                                                          <ResolvedDate>Thu, 26 Mar 2026 21:27:42 GMT</ResolvedDate>
                          <eventType>Informational</eventType>
                                                          <HowFound>Internal Monitoring</HowFound>
                                                        <guid isPermaLink="false">28696 at https://trust.zscaler.com</guid>
        <category domain="https://trust.zscaler.com">Advisory</category>
      </item>
          <item>
        <title>CBI Original URL Experience Degradation - zscaler.net, zscalerone.net, zscalertwo.net, zscloud.net, zscalerthree.net</title>
                <link>https://trust.zscaler.com/posts/28616</link>
                                <description>&lt;div id=&quot;post_body_wrapper_main&quot;&gt;&lt;div id=&quot;post_body_wrapper&quot;&gt;&lt;p&gt;&lt;span&gt;Zscaler is actively implementing mitigation measures for an intermittent, low-impact issue affecting the Zscaler Internet Access (ZIA) Service Edge.&amp;nbsp; As part of our troubleshooting and remediation process, we are making adjustments to a specific feature indicated by our data to be triggering the issue.&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;As a result, some Cloud Browser Isolation (CBI) customers who have enabled the newly released Original URL feature in their Isolation Profile may periodically still see the full CBI URL instead of the original URL.&amp;nbsp; While we understand this is a degradation in experience for end users, there should be no impact to core CBI functionality.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;div class=&quot;post-updates&quot; id=&quot;post-updates&quot;&gt;&lt;div class=&quot;update-list update-1&quot;&gt;&lt;p class=&quot;zs-update&quot;&gt;Update - &lt;span class=&quot;report-time&quot;&gt;Wed, 29 Apr 2026 17:22:03 UTC&lt;/span&gt;&lt;/p&gt;&lt;p&gt;The fix is now globally available across all clouds, and customers can proceed with feature enablement through the standard operational process.&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
                <pubDate>Fri, 20 Mar 2026 00:00:00 GMT</pubDate>
                                                                          <ResolvedDate>Wed, 29 Apr 2026 17:22:25 GMT</ResolvedDate>
                          <eventType>Informational</eventType>
                                  <customerImpact>Cloud Browser Isolation (CBI) Customers who have enabled the Original URL feature in an Isolation Profile.</customerImpact>
                                                                                <guid isPermaLink="false">28616 at https://trust.zscaler.com</guid>
        <category domain="https://trust.zscaler.com">Advisory</category>
      </item>
          <item>
        <title>SaaS Application Activity Data Not Displaying in Activity Logs - zscaler.net, zscalerone.net, zscalertwo.net, zscloud.net, zscalerthree.net</title>
                <link>https://trust.zscaler.com/posts/28551</link>
                                <description>&lt;div id=&quot;post_body_wrapper_main&quot;&gt;&lt;div id=&quot;post_body_wrapper&quot;&gt;&lt;p&gt;Activity Logs are currently not displaying SaaS application activity data. Zscaler is actively working to resolve this issue.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Who is impacted?&lt;/strong&gt;&lt;br&gt;ZIA customers who have onboarded and configured &lt;strong&gt;Data-at-Rest scanning for SaaS applications&lt;/strong&gt; may temporarily be unable to view SaaS-related activity data in Activity Logs.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;When will this be resolved?&lt;/strong&gt;&lt;br&gt;A fix is currently being deployed and is expected to be completed across all Zscaler clouds by &lt;strong&gt;March 22, 2026&lt;/strong&gt;.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;What are my next steps?&lt;/strong&gt;&lt;br&gt;No action is required from customers at this time. Zscaler will continue to monitor the deployment to ensure full restoration of activity log visibility.&lt;/p&gt;&lt;/div&gt;&lt;div class=&quot;latest-update&quot;&gt;&lt;p class=&quot;zs-update&quot;&gt;&lt;strong&gt;Latest Update - &lt;/strong&gt;&lt;span class=&quot;report-time&quot;&gt;Mon, 23 Mar 2026 04:09:49 UTC&lt;/span&gt;&lt;/p&gt;&lt;p&gt;The fix has been deployed on the remaining clouds and the issue is now resolved.&lt;/p&gt;&lt;/div&gt;&lt;div class=&quot;post-updates&quot; id=&quot;post-updates&quot;&gt;&lt;div class=&quot;update-list update-1&quot;&gt;&lt;p class=&quot;zs-update&quot;&gt;Update - &lt;span class=&quot;report-time&quot;&gt;Tue, 17 Mar 2026 06:28:51 UTC&lt;/span&gt;&lt;/p&gt;&lt;p&gt;As per the latest update, the fix has been deployed across the ZS1, ZSC, and ZSN clouds, and deployment on ZS2 and ZS3 is scheduled to complete by March 22, 2026.&lt;/p&gt;&lt;/div&gt;&lt;div class=&quot;update-list update-2&quot;&gt;&lt;p class=&quot;zs-update&quot;&gt;Update - &lt;span class=&quot;report-time&quot;&gt;Mon, 23 Mar 2026 04:09:49 UTC&lt;/span&gt;&lt;/p&gt;&lt;p&gt;The fix has been deployed on the remaining clouds and the issue is now resolved.&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
                <pubDate>Mon, 16 Mar 2026 00:00:00 GMT</pubDate>
                                                                          <ResolvedDate>Mon, 23 Mar 2026 04:10:00 GMT</ResolvedDate>
                          <eventType>Informational</eventType>
                                                                                                <guid isPermaLink="false">28551 at https://trust.zscaler.com</guid>
        <category domain="https://trust.zscaler.com">Advisory</category>
      </item>
          <item>
        <title>Deprecation of Individual Administrative UIs - zscaler.net, zscalerone.net, zscalertwo.net, zscloud.net, zscalerthree.net, private.zscaler.com, zdxcloud.net, zpatwo.net, zslogin.net</title>
                <link>https://trust.zscaler.com/posts/28546</link>
                                <description>&lt;p&gt;&lt;strong&gt;What is changing?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Zscaler is deprecating individual administrative User Interfaces (UIs). Customers must migrate to ZIdentity and Experience Center, Zscaler’s centralized administrative and insights platform, to take advantage of new features and innovations.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;strong&gt;Who is impacted?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;All customers not currently using ZIdentity for administrative purposes must complete the migration to have access to new features and innovations.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Key Information&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Access Experience Center:&lt;/strong&gt;&lt;span&gt; To use the latest administrative capabilities, customers must complete migration to ZIdentity for Administrators and access Experience Center (&lt;/span&gt;&lt;a href=&quot;https://console.zscaler.com/&quot;&gt;&lt;span&gt;https://console.zscaler.com&lt;/span&gt;&lt;/a&gt;&lt;span&gt;).&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Exclusive Features Beginning on April 1st&amp;nbsp; 2026:&lt;/strong&gt;&lt;span&gt; Starting in April 2026, all new features and product enhancements are available exclusively on Experience Center.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Innovations Exclusive to Experience Center:&lt;/strong&gt;&lt;span&gt; Risk360, Health360, Zero Trust Branch, and all future innovations are available only on Experience Center.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Legacy UIs Maintenance Mode on April 1st 2026:&lt;/strong&gt;&lt;span&gt; Legacy administrative UIs will go into maintenance mode starting in April 2026. This means you can still apply configuration changes in the legacy administrative UIs but no new features will be added to them. All new developments will be exclusive to the Experience Center.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Legacy UIs Deprecation on September 30th 2026:&lt;/strong&gt;&lt;span&gt; Legacy administrative UIs will be deprecated&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Executive dashboards with key insights that are showcased in the Executive Insights App (the new mobile CXO app) are only present in Experience Center.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;span&gt;To learn more, read our blog post:&amp;nbsp;&lt;/span&gt;&lt;a href=&quot;https://www.zscaler.com/blogs/product-insights/embracing-future-zero-trust-administration-zidentity-and-experience-center&quot;&gt;&lt;span&gt;Embracing the Future of Zero Trust Administration with ZIdentity and Experience Center&lt;/span&gt;&lt;/a&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;strong&gt;Next Steps&lt;/strong&gt;&lt;/p&gt;&lt;ol&gt;&lt;li&gt;&lt;strong&gt;Engage your Zscaler Account team:&lt;/strong&gt;&lt;span&gt; Your Zscaler Account team or Technical Success Manager can assist with planning and completing your migration to ZIdentity and enabling Experience Center.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Complete your migration to ZIdentity:&lt;/strong&gt;&lt;span&gt; Visit the&amp;nbsp;&lt;/span&gt;&lt;a href=&quot;https://info.zscaler.com/begin-your-zidentity-migration&quot;&gt;&lt;span&gt;ZIdentity migration page&lt;/span&gt;&lt;/a&gt;&lt;span&gt; to submit your request for migration. Review the&amp;nbsp;&lt;/span&gt;&lt;a href=&quot;https://help.zscaler.com/zidentity/migrating-zscaler-service-admins-zidentity&quot;&gt;&lt;span&gt;ZIdentity migration documentation&lt;/span&gt;&lt;/a&gt;&lt;span&gt; for detailed migration guidance. The time required to complete migration depends on your organization, but it can be as quick as setting up a new connection with your identity provider.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Start using the Experience Center at&amp;nbsp;&lt;/span&gt;&lt;a href=&quot;https://console.zscaler.com/&quot;&gt;&lt;span&gt;https://console.zscaler.com&lt;/span&gt;&lt;/a&gt;&lt;span&gt;.&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&lt;br&gt;&lt;strong&gt;What if I have more questions?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;If you have additional questions, contact Zscaler Support via the&amp;nbsp;&lt;/span&gt;&lt;strong&gt;Support&lt;/strong&gt;&lt;span&gt; link in the Zscaler Internet Access or ZIdentity Admin Portal, or call us at&amp;nbsp;&lt;/span&gt;&lt;strong&gt;+1 (408) 752-5885&lt;/strong&gt;&lt;span&gt;. Within the U.S., you can use&amp;nbsp;&lt;/span&gt;&lt;strong&gt;+1 (844) 971-0010&lt;/strong&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Update 3/25/26: Updated verbiage&lt;/li&gt;&lt;/ul&gt;</description>
                <pubDate>Mon, 16 Mar 2026 00:00:00 GMT</pubDate>
                                                                                  <eventType>Informational</eventType>
                                                                                                <guid isPermaLink="false">28546 at https://trust.zscaler.com</guid>
        <category domain="https://trust.zscaler.com">Advisory</category>
      </item>
          <item>
        <title>Sitereview Portal Validation Update - zscaler.net, zscalerone.net, zscalertwo.net, zscloud.net, zscalerthree.net, private.zscaler.com, zdxcloud.net, zpatwo.net, app.zsdpc.net, app.eu.zsdpc.net, zpabeta.net, zsdkone.net, zscalerrisk.net, admin.zscaleranalytics.net, zslogin.net</title>
                <link>https://trust.zscaler.com/posts/28536</link>
                                <description>&lt;p&gt;&lt;span&gt;Site review is used by customers and their users to submit URL categorization and review requests to Zscaler. To provide a more secure environment for our ZIA customers, Zscaler is refining how the Site review portal authorizes URL recategorization and review requests. Previously, the portal accepted requests if either the&amp;nbsp;&lt;/span&gt;&lt;strong&gt;Source IP&amp;nbsp;&lt;/strong&gt;&lt;span&gt;or&lt;/span&gt;&lt;strong&gt; the X Forwarded&lt;/strong&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;strong&gt;For&lt;/strong&gt;&lt;span&gt; header belonged to a Zscaler IP address range. As part of a security enhancement, we are removing reliance on the X Forwarded For header. Access will now be restricted to requests originating from a recognized Zscaler Source IP address range or an explicitly whitelisted non Zscaler Source IP.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;What Changed&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li data-list-item-id=&quot;e33130c944f15eebe5353822d799adb59&quot;&gt;&lt;strong&gt;Validation Logic Update:&amp;nbsp;&lt;/strong&gt;&lt;span&gt;We are moving from a model that allows either a Zscaler Source IP&amp;nbsp;&lt;/span&gt;&lt;strong&gt;OR&lt;/strong&gt;&lt;span&gt; a Zscaler XFF header to a model that requires a Zscaler Source IP.&lt;/span&gt;&lt;/li&gt;&lt;li data-list-item-id=&quot;eb358fd235bfc97bfb9c3e08467e9c41d&quot;&gt;&lt;strong&gt;Deprecation of XFF Headers:&lt;/strong&gt;&lt;span&gt; The portal will no longer consider the X-Forwarded-For header as a valid identifier for request origin.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Impacted Areas&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li data-list-item-id=&quot;e632109b219962d6c0131cddd3e84050f&quot;&gt;&lt;strong&gt;Service:&lt;/strong&gt;&lt;span&gt; Sitereview Portal (https://sitereview.zscaler.com/)&lt;/span&gt;&lt;/li&gt;&lt;li data-list-item-id=&quot;eea5d9614e43faa9b1891d31e92f859df&quot;&gt;&lt;strong&gt;Users:&lt;/strong&gt;&lt;span&gt; ZIA customers performing URL recategorization reviews.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;What is Not Allowed&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li data-list-item-id=&quot;ea4c6bfe6cd8ae83b62f4b4cb571df65b&quot;&gt;&lt;span&gt;Submissions from non-Zscaler Source IPs that rely solely on the XFF header to identify as a Zscaler customer will no longer be accepted.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;What is Allowed&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li data-list-item-id=&quot;e7b881c31bc80e3efc0241a2b51fe365d&quot;&gt;&lt;span&gt;Submissions originating from any valid Zscaler Source IP address.&lt;/span&gt;&lt;/li&gt;&lt;li data-list-item-id=&quot;ebc01643fcb27f21f0bdd82b2f1bd308a&quot;&gt;&lt;span&gt;Submissions from specific customer-owned (non-Zscaler) Source IPs that have been explicitly whitelisted by Zscaler.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Expected Behavior&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;To ensure minimal disruption, Zscaler has already proactively whitelisted known existing non-Zscaler Source IPs used by our customers. We expect most users to experience no change in service.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;For users where submission was previously working but stopped working after a change, they should do the following:&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li data-list-item-id=&quot;e62856ce660cdf8de08ed7a80274b2bec&quot;&gt;&lt;span&gt;Confirm they are accessing Sitereview from a Zscaler IP address (i.e., traffic is egressing through Zscaler).&lt;/span&gt;&lt;/li&gt;&lt;li data-list-item-id=&quot;e6adcc2dcdc6f872babc95109ab5810fa&quot;&gt;&lt;span&gt;If they must submit from a non-Zscaler egress IP, contact the Zscaler Support Team to request whitelisting (allowlisting) of their non-Zscaler Source IP.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Implementation Timeline&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;This update will be fully implemented after&amp;nbsp;&lt;/span&gt;&lt;strong&gt;April 4, 2026.&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Summary&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Zscaler is updating the request validation logic for the Sitereview portal (sitereview.zscaler.com) to enhance security. Effective&amp;nbsp;&lt;/span&gt;&lt;strong&gt;April 4, 2026&lt;/strong&gt;&lt;span&gt;, the portal will transition to strictly validating the Source IP address for all submissions.&lt;/span&gt;&lt;/p&gt;</description>
                <pubDate>Mon, 16 Mar 2026 00:00:00 GMT</pubDate>
                                                                          <ResolvedDate>Tue, 28 Apr 2026 13:36:09 GMT</ResolvedDate>
                          <eventType>Informational</eventType>
                                                                                                <guid isPermaLink="false">28536 at https://trust.zscaler.com</guid>
        <category domain="https://trust.zscaler.com">Advisory</category>
      </item>
          <item>
        <title>Commercial Salesforce Security Notification - zscaler.net, zscalerone.net, zscalertwo.net, zscloud.net, zscalerthree.net, private.zscaler.com, zdxcloud.net, zpatwo.net, app.zsdpc.net, app.eu.zsdpc.net, zpabeta.net, zsdkone.net, zscalerrisk.net, admin.zscaleranalytics.net, zslogin.net</title>
                <link>https://trust.zscaler.com/posts/28446</link>
                                <description>&lt;p&gt;&lt;span&gt;On March 10, 2026, Zscaler was made aware of a campaign targeted at the Salesforce Experience Center impacting a large number of Salesforce customers, including Zscaler.&amp;nbsp;Following&amp;nbsp;&lt;/span&gt;&lt;a href=&quot;https://www.salesforce.com/blog/protecting-your-data-essential-actions-to-secure-experience-cloud-guest-user-access/&quot;&gt;&lt;span&gt;guidance from Salesforce&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, Zscaler completed remediation of the incident on March 11, 2026.&lt;/span&gt;&lt;br&gt;&lt;br&gt;&lt;span&gt;Unauthorized access to personal data was limited to the Name and Email Address field from the Commercial Zscaler Community Portal. The scope of the incident was confined to the Zscaler Commercial Salesforce tenant and did not impact the Zscaler Federal Salesforce tenant.&lt;/span&gt;&lt;br&gt;&lt;br&gt;&lt;strong&gt;Zscaler&#039;s products, services and/or underlying systems and infrastructure were not impacted and no sensitive PII was accessed or exposed.&lt;/strong&gt;&lt;/p&gt;</description>
                <pubDate>Fri, 13 Mar 2026 00:00:00 GMT</pubDate>
                                                                          <ResolvedDate>Fri, 13 Mar 2026 16:35:16 GMT</ResolvedDate>
                          <eventType>Informational</eventType>
                                                          <HowFound>Internal Monitoring</HowFound>
                                                        <guid isPermaLink="false">28446 at https://trust.zscaler.com</guid>
        <category domain="https://trust.zscaler.com">Advisory</category>
      </item>
          <item>
        <title>Improved Input Validation for User-Editable Text Fields - zscaler.net, zscalerone.net, zscalertwo.net, zscloud.net, zscalerthree.net, private.zscaler.com, zdxcloud.net, zpatwo.net, app.zsdpc.net, app.eu.zsdpc.net, zpabeta.net, zsdkone.net, zscalerrisk.net, admin.zscaleranalytics.net, zslogin.net</title>
                <link>https://trust.zscaler.com/posts/28251</link>
                                <description>&lt;div id=&quot;post_body_wrapper&quot;&gt;&lt;p&gt;&lt;span&gt;We’ve enhanced validation for certain user-editable fields to ensure user-provided values remain plain text and render consistently across the UI (including tables, tooltips, and logs).&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;What Changed&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;ZIA now enforces stricter validation on specific text fields to prevent the use of:&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;HTML / markup&lt;/strong&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;HTML-encoded markup / HTML entities&amp;nbsp;&lt;/strong&gt;&lt;span&gt;(including entity-based representations of special characters or whitespace)&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;span&gt;If disallowed input is detected, the API will reject the request with HTTP 400 (Bad Request).&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Impacted Areas (where this validation applies)&lt;/strong&gt;&lt;/p&gt;&lt;div&gt;&lt;table&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Impacted Areas&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;KB Document&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Webhook names&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://help.zscaler.com/zia/adding-webhook&quot;&gt;https://help.zscaler.com/zia/adding-webhook&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;PAC file names &amp;amp; descriptions&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://help.zscaler.com/zia/about-hosted-pac-files&quot;&gt;https://help.zscaler.com/zia/about-hosted-pac-files&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Static IP descriptions&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://help.zscaler.com/zia/self-provisioning-static-ip-addresses&quot;&gt;https://help.zscaler.com/zia/self-provisioning-static-ip-addresses&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;URLs in URL categories&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://help.zscaler.com/zia/configuring-custom-url-categories&quot;&gt;https://help.zscaler.com/zia/configuring-custom-url-categories&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Extranet names&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://help.zscaler.com/zia/configuring-extranet&quot;&gt;https://help.zscaler.com/zia/configuring-extranet&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Location group names&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://help.zscaler.com/zia/configuring-dynamic-location-groups&quot;&gt;https://help.zscaler.com/zia/configuring-dynamic-location-groups&lt;/a&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;p&gt;&lt;strong&gt;What Is Not Allowed (Rejected with HTTP 400)&lt;/strong&gt;&lt;/p&gt;&lt;ol&gt;&lt;li&gt;&lt;span&gt;HTML / Markup in Input Fields Examples (NOT allowed):&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;poc&amp;lt;a href=&quot;...&quot;&amp;gt;X&amp;lt;/a&amp;gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;&amp;lt;script&amp;gt;alert(1)&amp;lt;/script&amp;gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;&amp;lt;img src=x onerror=alert(1)&amp;gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;&amp;lt;svg onload=alert(1)&amp;gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;HTML-Encoded Markup / HTML Entities Examples (NOT allowed):&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;&amp;amp;lt; , &amp;amp;gt; (encoded &amp;lt; and &amp;gt;)&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;&amp;amp;Tab; (encoded tab)&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;poc&amp;amp;lt;a href=javascript:confirm(document.domain)&amp;amp;gt;X&amp;amp;lt;/a&amp;amp;gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&lt;strong&gt;What Is Allowed&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Plain text values that do not contain HTML markup or HTML entity encodings.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Example (allowed):&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;Webhook for audit notifications - test environment&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Expected Behavior / User Impact&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;Requests containing disallowed content are rejected with HTTP 400 (Bad Request).&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;The object will not be created/updated with the invalid value.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;This ensures user-provided values render predictably in UI locations such as tables, tooltips, and audit logs.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Implementation Timeline&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;Starting from 15 March&lt;/span&gt;&lt;strong&gt;,&lt;/strong&gt;&lt;span&gt; we will begin the update rollout process.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;The rollout will be performed cloud-by-cloud (each production cloud will be updated one by one).&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;By 31 March, the update is expected to be deployed across all production clouds.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Summary&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;As part of a product hardening enhancement, the API now rejects inputs containing HTML markup or HTML entity-encoded markup in select user-editable fields (e.g., webhook names, PAC file metadata, URL category URLs, and naming/description fields). Requests with such values will return HTTP 400.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;For any further information, please feel free to reach out to the Zscaler Support team.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</description>
                <pubDate>Fri, 06 Mar 2026 00:00:00 GMT</pubDate>
                                                                                  <eventType>Informational</eventType>
                                                                                                <guid isPermaLink="false">28251 at https://trust.zscaler.com</guid>
        <category domain="https://trust.zscaler.com">Advisory</category>
      </item>
          <item>
        <title>VPN Legacy Application Issue - private.zscaler.com</title>
                <link>https://trust.zscaler.com/posts/28211</link>
                                <description>&lt;p&gt;Zscaler continues to monitor the &lt;a href=&quot;https://trust.zscaler.com/private.zscaler.com/posts/28196&quot;&gt;&lt;strong&gt;previously reported service disruption&lt;/strong&gt;&lt;/a&gt; impacting private.zscaler.com, affecting access to VPN Legacy Applications for a subset of users.&lt;/p&gt;&lt;p&gt;Initial telemetry and early recovery indicators suggested that service behavior had stabilized; however, subsequent monitoring has confirmed that intermittent impact remains for a subset of users. According to the cloud provider’s status page, &lt;strong&gt;two Availability Zones (mec1-az2 and mec1-az3) in the AWS ME-CENTRAL-1 Region&lt;/strong&gt; are currently experiencing impairment, and AWS is actively working toward full restoration.&lt;/p&gt;&lt;p&gt;Customers may refer to the cloud provider’s status page for additional updates related to the underlying infrastructure &lt;a href=&quot;https://health.aws.amazon.com/health/status&quot;&gt;&lt;strong&gt;Status Page&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;.&lt;/strong&gt;&lt;a href=&quot;https://health.aws.amazon.com/health/status&quot;&gt;&lt;span class=&quot;ms-0.5 inline-block align-middle leading-none&quot;&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Zscaler continues close monitoring of the situation and will provide further updates as additional information becomes available or once full service stability is confirmed. Customers requiring assistance or continuing to experience impact are encouraged to contact &lt;strong&gt;Zscaler Support&lt;/strong&gt; for further investigation and guidance.&lt;/p&gt;</description>
                <pubDate>Mon, 02 Mar 2026 00:00:00 GMT</pubDate>
                                                                                  <eventType>Informational</eventType>
                                  <customerImpact>Customers may experience issue with ZPA &quot;VPN legacy&quot; services.</customerImpact>
                                                                                <guid isPermaLink="false">28211 at https://trust.zscaler.com</guid>
        <category domain="https://trust.zscaler.com">Advisory</category>
      </item>
          <item>
        <title>VPN Legacy Application Issue - private.zscaler.com</title>
                <link>https://trust.zscaler.com/posts/28196</link>
                                <description>&lt;div id=&quot;post_body_wrapper_main&quot;&gt;&lt;div id=&quot;post_body_wrapper&quot;&gt;&lt;p class=&quot;post_body&quot; id=&quot;post_body&quot;&gt;Zscaler is currently investigating an issue affecting Legacy VPN application services for customers in the UAE region. Initial findings indicate that this disruption is related to an AWS service issue within Availability Zone mec1-az2 in the ME-CENTRAL-1 region.&lt;br&gt;&lt;br&gt;Our operations team is monitoring the situation closely and working toward mitigation. We will provide further updates as more information becomes available.&lt;br&gt;&lt;br&gt;We will continue to provide updates here as the investigation progresses. For detailed updates, please check the Service Status section in your &lt;a href=&quot;https://community.zscaler.com/zenith/s/Guides/aSoPJ0000005aMD0AY/how-to-access-customer-support-portal-csp-and-view-the-service-status-section&quot;&gt;Zscaler customer support portal (CSP).&lt;/a&gt; Status changes and additional details will be posted there as they become available.&lt;/p&gt;&lt;/div&gt;&lt;div class=&quot;latest-update&quot;&gt;&lt;p class=&quot;zs-update&quot;&gt;&lt;strong&gt;Latest Update - &lt;/strong&gt;&lt;span class=&quot;report-time&quot;&gt;Mon, 02 Mar 2026 02:47:13 UTC&lt;/span&gt;&lt;/p&gt;&lt;p&gt;The AWS service disruption has recovered, and Zscaler is considering this issue resolved.&lt;/p&gt;&lt;/div&gt;&lt;div class=&quot;post-updates&quot; id=&quot;post-updates&quot;&gt;&lt;div class=&quot;update-list update-1&quot;&gt;&lt;p class=&quot;zs-update&quot;&gt;Update - &lt;span class=&quot;report-time&quot;&gt;Sun, 01 Mar 2026 17:23:03 UTC&lt;/span&gt;&lt;/p&gt;&lt;p&gt;An issue within AWS was identified, and Zscaler teams are actively working to address and mitigate the problem.&lt;/p&gt;&lt;/div&gt;&lt;div class=&quot;update-list update-2&quot;&gt;&lt;p class=&quot;zs-update&quot;&gt;Update - &lt;span class=&quot;report-time&quot;&gt;Mon, 02 Mar 2026 02:47:13 UTC&lt;/span&gt;&lt;/p&gt;&lt;p&gt;The AWS service disruption has recovered, and Zscaler is considering this issue resolved.&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
                <pubDate>Sun, 01 Mar 2026 00:00:00 GMT</pubDate>
                                                                          <ResolvedDate>Mon, 02 Mar 2026 02:49:24 GMT</ResolvedDate>
                          <eventType>Informational</eventType>
                                  <customerImpact>Customers may have experienced issue with ZPA &quot;VPN legacy&quot; services.</customerImpact>
                                                                                <guid isPermaLink="false">28196 at https://trust.zscaler.com</guid>
        <category domain="https://trust.zscaler.com">Advisory</category>
      </item>
          <item>
        <title>Middle East Situation and Elevated Monitoring Posture - zscaler.net, zscalerone.net, zscalertwo.net, zscloud.net, zscalerthree.net, private.zscaler.com, zdxcloud.net, zpatwo.net</title>
                <link>https://trust.zscaler.com/posts/28186</link>
                                <description>&lt;p&gt;&lt;span&gt;Zscaler is aware of ongoing geopolitical developments in the Middle East that may impact regional internet connectivity and routing. As part of our standard operational practices, Zscaler is closely monitoring global network conditions and internet infrastructure stability to help maintain continued service reliability for our customers.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;As of February 28, 2026, Zscaler services are operating normally, and we have not observed any impact to platform availability, performance, or security services.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Zscaler continuously monitors external factors that may influence internet routing, regional connectivity, and cybersecurity risk levels. In light of current conditions, we have increased operational monitoring and readiness measures across our global cloud infrastructure as a precautionary step to support service resilience.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Current Service Status&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;All Zscaler services are operating normally.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;As of February 28, 2026, no disruption has been observed Traffic processing, policy enforcement, and security inspection capabilities are functioning as expected.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Operational Readiness&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Zscaler operates a globally distributed cloud platform designed for high availability and continuity. Our operational teams are:&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;Monitoring global internet health, routing stability, and infrastructure conditions&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Monitoring cybersecurity threat activity and indicators relevant to customer environments&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Prepared to take proactive mitigation actions, if required, to maintain service stability and protection&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Customer Guidance&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;No customer action is required at this time.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Customers may continue normal operations. Zscaler will update this advisory on this page and through official communication channels should any service impact occur or additional guidance become necessary.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;</description>
                <pubDate>Sat, 28 Feb 2026 00:00:00 GMT</pubDate>
                                                                                  <eventType>Informational</eventType>
                                                                                                <guid isPermaLink="false">28186 at https://trust.zscaler.com</guid>
        <category domain="https://trust.zscaler.com">Advisory</category>
      </item>
          <item>
        <title>Zscaler Client Connector for VDI – Version 1.7 Upgrade Issue - zscaler.net, zscalertwo.net, zscloud.net, zscalerthree.net</title>
                <link>https://trust.zscaler.com/posts/28091</link>
                                <description>&lt;div id=&quot;post_body_wrapper_main&quot;&gt;&lt;div id=&quot;post_body_wrapper_main&quot;&gt;&lt;div id=&quot;post_body_wrapper&quot;&gt;&lt;p&gt;&lt;span&gt;Zscaler is investigating an issue affecting customers who upgraded the Zscaler&lt;/span&gt;&lt;strong&gt; Client Connector for Virtual Desktop Infrastructure (VDI)&lt;/strong&gt;&lt;span&gt; to versions&amp;nbsp;&lt;/span&gt;&lt;strong&gt;1.7.0.4&lt;/strong&gt;, &lt;strong&gt;1.7.0.6&lt;/strong&gt;, or &lt;strong&gt;1.7.0.7&lt;/strong&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Following the upgrade, some VDI instances may remain in an&amp;nbsp;&lt;/span&gt;&lt;strong&gt;“off” state&lt;/strong&gt;&lt;span&gt; due to authentication failures. As a result, impacted VDIs may be unable to establish a connection to the Zscaler service.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Zscaler has identified the issue and validated that reverting to version&amp;nbsp;&lt;/span&gt;&lt;strong&gt;1.6&lt;/strong&gt;&lt;span&gt; restores expected functionality. A permanent fix is currently under validation.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Who is impacted?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;You may be impacted if:&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;You are using&amp;nbsp;&lt;/span&gt;&lt;strong&gt;Zscaler Client Connector (ZCC) for VDI&lt;/strong&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;You upgraded to&amp;nbsp;&lt;/span&gt;&lt;strong&gt;version 1.7.0.4, 1.7.0.6, or 1.7.0.7&lt;/strong&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Your VDI instances are showing an&amp;nbsp;&lt;/span&gt;&lt;strong&gt;“off” state&lt;/strong&gt;&lt;span&gt; and failing authentication&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Customers who remain on&amp;nbsp;version 1.6 or lower are&amp;nbsp;not impacted.&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;What are my next steps?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;If you have upgraded to version &lt;strong&gt;1.7.0.4, 1.7.0.6, or 1.7.0.7&lt;/strong&gt;:&lt;/span&gt;&lt;/p&gt;&lt;ol&gt;&lt;li&gt;&lt;strong&gt;Downgrade Zscaler Client Connector for VDI to version 1.6&lt;/strong&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Validate that the Client Connector Service Status is&amp;nbsp;&lt;/span&gt;&lt;strong&gt;“ON”&lt;/strong&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&lt;span&gt;This downgrade has been validated as a stable interim mitigation. We recommend pausing any additional rollouts of version 1.7 until further notice.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;What if I have more questions?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;If you require assistance with the rollback process or need further clarification, please contact Support.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;post-updates&quot; id=&quot;post-updates&quot;&gt;&lt;div class=&quot;update-list update-1&quot;&gt;&lt;p class=&quot;zs-update&quot;&gt;Update - &lt;span class=&quot;report-time&quot;&gt;Wed, 11 Mar 2026 23:03:48 UTC&lt;/span&gt;&lt;/p&gt;&lt;p&gt;Zscaler has released &lt;a href=&quot;https://help.zscaler.com/cloud-branch-connector/zscaler-client-connector-vdi-release-summary-2026?applicable_category=Windows&amp;amp;applicable_version=1.7.0.10&amp;amp;deployment_date=2026-03-11&amp;amp;id=1538798&quot;&gt;Zscaler Client Connector for VDI version 1.7.0.10&lt;/a&gt;, which includes the fix for the reported issue. By end of day, the 1.7.0.10 image will be made available in the Client Connector App Store within the Client Connector UI, allowing customers to download and deploy the updated image directly. Customers experiencing this issue are advised to upgrade to this version once it becomes available.&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
                <pubDate>Wed, 25 Feb 2026 00:00:00 GMT</pubDate>
                                                                          <ResolvedDate>Wed, 11 Mar 2026 23:04:59 GMT</ResolvedDate>
                          <eventType>Informational</eventType>
                                                                                                <guid isPermaLink="false">28091 at https://trust.zscaler.com</guid>
        <category domain="https://trust.zscaler.com">Advisory</category>
      </item>
      </channel>
</rss>
