<rss version="2.0" xml:base="https://trust.zscaler.com/rss-feed/advisories" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>Trust</title>
    <link>https://trust.zscaler.com/rss-feed/advisories</link>
    <description>Trust Post Feeds.</description>
        <generator>trust.zscaler.com</generator>
    <language>en-us</language>
    <atom:link href="https://trust.zscaler.com/rss-feed/advisories" rel="self" type="application/rss+xml"/>
              <item>
        <title>Axios Supply Chain Attack Update - zscaler.net, zscalerone.net, zscalertwo.net, zscloud.net, zscalerthree.net, private.zscaler.com, zdxcloud.net, zpatwo.net, app.zsdpc.net, app.eu.zsdpc.net, zpabeta.net, zsdkone.net, zscalerrisk.net, admin.zscaleranalytics.net, zslogin.net</title>
                <link>https://trust.zscaler.com/posts/28816</link>
                                <description>&lt;p&gt;&lt;span&gt;Zscaler has analyzed the supply chain compromises affecting the Axios npm packages.&amp;nbsp;&lt;/span&gt;&lt;strong&gt;Analysis confirms no impact to Zscaler platforms, products, or internal systems&lt;/strong&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;As a best practice, customers should review their environments for the following impacted versions:&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Axios npm package versions:&lt;span&gt; 1.14.1 and 0.30.4&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;span&gt;Actions if you have an impacted version:&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Update/Revert:&amp;nbsp;&lt;span&gt;Revert or pin Axios to known safe versions (e.g., 1.14.0 or 0.30.3)&lt;/span&gt;&lt;/li&gt;&lt;li&gt;Rotate Credentials:&amp;nbsp;&lt;span&gt;Update all API keys, cloud tokens, and environment variables associated with this library.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;span&gt;Zscaler will continue to monitor the situation and update this post if new information emerges.&lt;/span&gt;&lt;/p&gt;</description>
                <pubDate>Fri, 03 Apr 2026 17:10:27 GMT</pubDate>
                                                                          <eventType>Informational</eventType>
                                                <guid isPermaLink="false">28816 at https://trust.zscaler.com</guid>
        <category domain="https://trust.zscaler.com">Advisory</category>
      </item>
          <item>
        <title>Action Required — Verify/Correct Your Z-Identity IdP “Primary Email” Attribute Mapping  - zscaler.net, zscalerone.net, zscalertwo.net, zscloud.net, zscalerthree.net, private.zscaler.com, zdxcloud.net, zpatwo.net, app.zsdpc.net, app.eu.zsdpc.net, zpabeta.net, zsdkone.net, zscalerrisk.net, admin.zscaleranalytics.net, zslogin.net</title>
                <link>https://trust.zscaler.com/posts/28776</link>
                                <description>&lt;p&gt;&lt;span&gt;Zscaler is proactively reaching out to help prevent potential login failures to the&amp;nbsp;Z-Identity Admin Console when authenticating through your&amp;nbsp;Identity Provider (IdP). Based on monitoring, your tenant may be&amp;nbsp;missing or mis-mapping the required&amp;nbsp;Primary Email attribute used during&amp;nbsp;JIT (Just-In-Time) provisioning.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;This advisory relates to the recent incident and follow-up corrective actions (Reference: Trust Post:&amp;nbsp;&lt;/span&gt;&lt;a href=&quot;https://trust.zscaler.com/zslogin.net/posts/28626&quot;&gt;&lt;em&gt;Z-Identity Portal Issue&lt;/em&gt;&lt;/a&gt;&lt;span&gt;).&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;What is the issue?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;On&amp;nbsp;Mar 21st, some customers experienced login failures to the Z-Identity Admin Console when authenticating via their IdP. The error observed was:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;“Invalid Input Error: Primary Email is required.”&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Why this is needed&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Zscaler deployed an update to improve validation of attributes during&amp;nbsp;JIT provisioning. A subset of customers encountered login failures where the IdP was&amp;nbsp;not sending the required email attribute or it was&amp;nbsp;incorrectly mapped. To restore stability, Zscaler&amp;nbsp;reverted the change.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Zscaler is now running a&amp;nbsp;monitoring-only period and asking customers to validate/correct mappings&amp;nbsp;before the improved validation is re-enabled in a controlled manner.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Who is impacted?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;You may be impacted if all of the following apply:&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;IdP-based authentication is enabled (SSO via Google Workspace, Azure AD, Okta, etc.)&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;JIT provisioning is enabled&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;The&amp;nbsp;Primary Email attribute mapping is&amp;nbsp;missing or incorrect (wrong attribute name or not present in the IDP assertion)&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;span&gt;Why JIT matters: JIT synchronizes user attributes from the IdP to Z-Identity at login; missing/incorrect Primary Email mapping is most likely to cause failures when validation is re-enabled.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Action Required — Verify your IdP “Primary Email” attribute mapping&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Quick verification steps&lt;/span&gt;&lt;/p&gt;&lt;ol&gt;&lt;li&gt;&lt;span&gt;Confirm IDP assertion includes an email address&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;In your IdP admin console, open the&amp;nbsp;Zscaler Z-Identity IDP app configuration.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Use&amp;nbsp;Test / Preview IDP Response.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Verify an&amp;nbsp;email attribute is present and contains the user’s email address.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Confirm attribute/claim mapping matches the assertion&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;Review your IdP attribute/claim mappings.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Ensure the mapped attribute name matches the actual attribute name in the assertion.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Recommended: Test with JIT provisioning&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;Create a&amp;nbsp;new test user in the IdP that does&amp;nbsp;not exist in Z-Identity.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Attempt login to the&amp;nbsp;Z-Identity Admin Console via IdP.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Expected results:&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;If the user is created successfully → mapping is correct.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;If you see&amp;nbsp;“Primary Email is required” → mapping needs correction.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&lt;span&gt;If your test fails (remediation)&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;Update the IdP mapping to use the&amp;nbsp;correct email attribute name&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Ensure the email attribute is included in the IDP assertion&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Re-test using a&amp;nbsp;new JIT user&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Notify your&amp;nbsp;TSM/Zscaler Support once corrected&amp;nbsp;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Timeline / next steps&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Zscaler plans to re-enable the updated validation in approximately&amp;nbsp;three weeks. Customers are requested to remediate&amp;nbsp;before April 15th to ensure adequate time for correction and testing.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Support / escalation&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;If you need help validating the IDP assertion or correcting the mapping, contact&amp;nbsp;Zscaler Support and include:&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;Your&amp;nbsp;IdP vendor/type&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Screenshot/description of your&amp;nbsp;email attribute/claim mapping&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;(If available) the&amp;nbsp;attribute name used for email in the IDP assertion (no sensitive data required)&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;</description>
                <pubDate>Tue, 31 Mar 2026 06:45:12 GMT</pubDate>
                                                                          <eventType>Under Investigation</eventType>
                                                <guid isPermaLink="false">28776 at https://trust.zscaler.com</guid>
        <category domain="https://trust.zscaler.com">Advisory</category>
      </item>
          <item>
        <title>Experience Center – SSO Error When Accessing Support Tab - zslogin.net</title>
                <link>https://trust.zscaler.com/posts/28726</link>
                                <description>&lt;div id=&quot;post_body_wrapper_main&quot;&gt;&lt;div id=&quot;post_body_wrapper_main&quot;&gt;&lt;div id=&quot;post_body_wrapper&quot;&gt;&lt;p&gt;&lt;span&gt;Zscaler is investigating an issue impacting Experience Center customers, where users may encounter an SSO error when navigating to the Support tab within the Experience Portal.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Impact: &lt;/strong&gt;&lt;span&gt;Customers attempting to access the Support tab through the Experience Center portal may be unable to successfully authenticate via SSO. All other platform functionalities remain unaffected.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Workaround:&lt;/strong&gt;&lt;br&gt;&lt;span&gt;Customers can continue to access the Support Portal using the following validated workaround:&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;Log in to an alternate Zscaler Product Admin Portal (e.g., ZIA, ZPA, or ZDX)&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Navigate to the Support Portal from that product interface&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;From there:&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;View existing cases across all products, including Experience Center, or&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Create a new case and manually select:&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Product:&lt;/strong&gt;&lt;span&gt; Experience Center&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Company ID:&lt;/strong&gt;&lt;span&gt; Corresponding Experience Center tenant&amp;nbsp;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;span&gt;Zscaler has identified the underlying cause of the issue and a fix has been developed. Deployment of the fix is currently planned for&amp;nbsp;&lt;/span&gt;&lt;strong&gt;March 28, 2026, &lt;/strong&gt;during the&lt;strong&gt; &lt;/strong&gt;&lt;a href=&quot;https://trust.zscaler.com/zslogin.net/maintenance&quot;&gt;&lt;strong&gt;Maintenance Window&lt;/strong&gt;&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;Update - &lt;span class=&quot;report-time&quot;&gt;Sat, 28 Mar 2026 09:59:05 UTC&lt;/span&gt;&lt;/p&gt;&lt;p&gt;Zscaler has deployed a fix, and the issue impacting access to the Support tab in the Experience Center portal has been resolved. Services have been restored, and customers should now be able to access Support functionality normally. Zscaler will continue to monitor the environment to ensure ongoing stability.&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
                <pubDate>Fri, 27 Mar 2026 00:53:10 GMT</pubDate>
                                                                          <eventType>Informational</eventType>
                                                <guid isPermaLink="false">28726 at https://trust.zscaler.com</guid>
        <category domain="https://trust.zscaler.com">Advisory</category>
      </item>
          <item>
        <title>Trivy and LiteLLM Supply Chain Incident (CVE-2026-33634) Update - zscaler.net, zscalerone.net, zscalertwo.net, zscloud.net, zscalerthree.net, private.zscaler.com, zdxcloud.net, zpatwo.net, app.zsdpc.net, app.eu.zsdpc.net, zpabeta.net, zsdkone.net, zscalerrisk.net, admin.zscaleranalytics.net, zslogin.net</title>
                <link>https://trust.zscaler.com/posts/28696</link>
                                <description>&lt;div id=&quot;post_body_wrapper&quot;&gt;&lt;p&gt;&lt;span&gt;Zscaler has analyzed the supply chain compromises affecting the Trivy security scanner and LiteLLM.&amp;nbsp;&lt;/span&gt;&lt;strong&gt;Analysis confirms no impact to Zscaler platforms, products, or internal systems, including AI Guard&lt;/strong&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;As a best practice customers should review their environments for the following impacted versions:&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Trivy:&lt;/strong&gt;&lt;span&gt; Container images&amp;nbsp;v0.69.5–v0.69.6&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;LiteLLM:&amp;nbsp;&lt;/strong&gt;&lt;span&gt;Versions&amp;nbsp;1.82.7 and&amp;nbsp;1.82.8.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;span&gt;Actions if you have an impacted version:&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Update/Revert:&amp;nbsp;&lt;/strong&gt;&lt;span&gt;Upgrade Trivy to&amp;nbsp;v0.69.7 or later and downgrade LiteLLM to&amp;nbsp;v1.82.6.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Rotate Credentials:&amp;nbsp;&lt;/strong&gt;&lt;span&gt;Update all API keys, cloud tokens, and environment variables associated with these tools.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;span&gt;Zscaler will continue to monitor the situation and update this post if new information emerges.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</description>
                <pubDate>Thu, 26 Mar 2026 21:18:45 GMT</pubDate>
                                                                          <eventType>Informational</eventType>
                                                <guid isPermaLink="false">28696 at https://trust.zscaler.com</guid>
        <category domain="https://trust.zscaler.com">Advisory</category>
      </item>
          <item>
        <title>CBI Original URL Experience Degradation - zscaler.net, zscalerone.net, zscalertwo.net, zscloud.net, zscalerthree.net</title>
                <link>https://trust.zscaler.com/posts/28616</link>
                                <description>&lt;div id=&quot;post_body_wrapper&quot;&gt;&lt;p&gt;&lt;span&gt;Zscaler is actively implementing mitigation measures for an intermittent, low-impact issue affecting the Zscaler Internet Access (ZIA) Service Edge.&amp;nbsp; As part of our troubleshooting and remediation process, we are making adjustments to a specific feature indicated by our data to be triggering the issue.&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;As a result, some Cloud Browser Isolation (CBI) customers who have enabled the newly released Original URL feature in their Isolation Profile may periodically still see the full CBI URL instead of the original URL.&amp;nbsp; While we understand this is a degradation in experience for end users, there should be no impact to core CBI functionality.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</description>
                <pubDate>Fri, 20 Mar 2026 21:17:56 GMT</pubDate>
                                                                          <eventType>Informational</eventType>
                                  <customerImpact>Cloud Browser Isolation (CBI) Customers who have enabled the Original URL feature in an Isolation Profile.</customerImpact>
                                <guid isPermaLink="false">28616 at https://trust.zscaler.com</guid>
        <category domain="https://trust.zscaler.com">Advisory</category>
      </item>
          <item>
        <title>SaaS Application Activity Data Not Displaying in Activity Logs - zscaler.net, zscalerone.net, zscalertwo.net, zscloud.net, zscalerthree.net</title>
                <link>https://trust.zscaler.com/posts/28551</link>
                                <description>&lt;div id=&quot;post_body_wrapper_main&quot;&gt;&lt;div id=&quot;post_body_wrapper&quot;&gt;&lt;p&gt;Activity Logs are currently not displaying SaaS application activity data. Zscaler is actively working to resolve this issue.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Who is impacted?&lt;/strong&gt;&lt;br&gt;ZIA customers who have onboarded and configured &lt;strong&gt;Data-at-Rest scanning for SaaS applications&lt;/strong&gt; may temporarily be unable to view SaaS-related activity data in Activity Logs.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;When will this be resolved?&lt;/strong&gt;&lt;br&gt;A fix is currently being deployed and is expected to be completed across all Zscaler clouds by &lt;strong&gt;March 22, 2026&lt;/strong&gt;.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;What are my next steps?&lt;/strong&gt;&lt;br&gt;No action is required from customers at this time. Zscaler will continue to monitor the deployment to ensure full restoration of activity log visibility.&lt;/p&gt;&lt;/div&gt;&lt;div class=&quot;latest-update&quot;&gt;&lt;p class=&quot;zs-update&quot;&gt;&lt;strong&gt;Latest Update - &lt;/strong&gt;&lt;span class=&quot;report-time&quot;&gt;Mon, 23 Mar 2026 04:09:49 UTC&lt;/span&gt;&lt;/p&gt;&lt;p&gt;The fix has been deployed on the remaining clouds and the issue is now resolved.&lt;/p&gt;&lt;/div&gt;&lt;div class=&quot;post-updates&quot; id=&quot;post-updates&quot;&gt;&lt;div class=&quot;update-list update-1&quot;&gt;&lt;p class=&quot;zs-update&quot;&gt;Update - &lt;span class=&quot;report-time&quot;&gt;Tue, 17 Mar 2026 06:28:51 UTC&lt;/span&gt;&lt;/p&gt;&lt;p&gt;As per the latest update, the fix has been deployed across the ZS1, ZSC, and ZSN clouds, and deployment on ZS2 and ZS3 is scheduled to complete by March 22, 2026.&lt;/p&gt;&lt;/div&gt;&lt;div class=&quot;update-list update-2&quot;&gt;&lt;p class=&quot;zs-update&quot;&gt;Update - &lt;span class=&quot;report-time&quot;&gt;Mon, 23 Mar 2026 04:09:49 UTC&lt;/span&gt;&lt;/p&gt;&lt;p&gt;The fix has been deployed on the remaining clouds and the issue is now resolved.&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
                <pubDate>Mon, 16 Mar 2026 21:54:12 GMT</pubDate>
                                                                          <eventType>Informational</eventType>
                                                <guid isPermaLink="false">28551 at https://trust.zscaler.com</guid>
        <category domain="https://trust.zscaler.com">Advisory</category>
      </item>
          <item>
        <title>Deprecation of Individual Administrative UIs - zscaler.net, zscalerone.net, zscalertwo.net, zscloud.net, zscalerthree.net, private.zscaler.com, zdxcloud.net, zpatwo.net, zslogin.net</title>
                <link>https://trust.zscaler.com/posts/28546</link>
                                <description>&lt;p&gt;&lt;strong&gt;What is changing?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Zscaler is deprecating individual administrative User Interfaces (UIs). Customers must migrate to ZIdentity and Experience Center, Zscaler’s centralized administrative and insights platform, to take advantage of new features and innovations.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;strong&gt;Who is impacted?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;All customers not currently using ZIdentity for administrative purposes must complete the migration to have access to new features and innovations.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Key Information&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Access Experience Center:&lt;/strong&gt;&lt;span&gt; To use the latest administrative capabilities, customers must complete migration to ZIdentity for Administrators and access Experience Center (&lt;/span&gt;&lt;a href=&quot;https://console.zscaler.com/&quot;&gt;&lt;span&gt;https://console.zscaler.com&lt;/span&gt;&lt;/a&gt;&lt;span&gt;).&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Exclusive Features Beginning on April 1st&amp;nbsp; 2026:&lt;/strong&gt;&lt;span&gt; Starting in April 2026, all new features and product enhancements are available exclusively on Experience Center.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Innovations Exclusive to Experience Center:&lt;/strong&gt;&lt;span&gt; Risk360, Health360, Zero Trust Branch, and all future innovations are available only on Experience Center.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Legacy UIs Maintenance Mode on April 1st 2026:&lt;/strong&gt;&lt;span&gt; Legacy administrative UIs will go into maintenance mode starting in April 2026. This means you can still apply configuration changes in the legacy administrative UIs but no new features will be added to them. All new developments will be exclusive to the Experience Center.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Legacy UIs Deprecation on September 30th 2026:&lt;/strong&gt;&lt;span&gt; Legacy administrative UIs will be deprecated&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Executive dashboards with key insights that are showcased in the Executive Insights App (the new mobile CXO app) are only present in Experience Center.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;span&gt;To learn more, read our blog post:&amp;nbsp;&lt;/span&gt;&lt;a href=&quot;https://www.zscaler.com/blogs/product-insights/embracing-future-zero-trust-administration-zidentity-and-experience-center&quot;&gt;&lt;span&gt;Embracing the Future of Zero Trust Administration with ZIdentity and Experience Center&lt;/span&gt;&lt;/a&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;strong&gt;Next Steps&lt;/strong&gt;&lt;/p&gt;&lt;ol&gt;&lt;li&gt;&lt;strong&gt;Engage your Zscaler Account team:&lt;/strong&gt;&lt;span&gt; Your Zscaler Account team or Technical Success Manager can assist with planning and completing your migration to ZIdentity and enabling Experience Center.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Complete your migration to ZIdentity:&lt;/strong&gt;&lt;span&gt; Visit the&amp;nbsp;&lt;/span&gt;&lt;a href=&quot;https://info.zscaler.com/begin-your-zidentity-migration&quot;&gt;&lt;span&gt;ZIdentity migration page&lt;/span&gt;&lt;/a&gt;&lt;span&gt; to submit your request for migration. Review the&amp;nbsp;&lt;/span&gt;&lt;a href=&quot;https://help.zscaler.com/zidentity/migrating-zscaler-service-admins-zidentity&quot;&gt;&lt;span&gt;ZIdentity migration documentation&lt;/span&gt;&lt;/a&gt;&lt;span&gt; for detailed migration guidance. The time required to complete migration depends on your organization, but it can be as quick as setting up a new connection with your identity provider.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Start using the Experience Center at&amp;nbsp;&lt;/span&gt;&lt;a href=&quot;https://console.zscaler.com/&quot;&gt;&lt;span&gt;https://console.zscaler.com&lt;/span&gt;&lt;/a&gt;&lt;span&gt;.&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&lt;br&gt;&lt;strong&gt;What if I have more questions?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;If you have additional questions, contact Zscaler Support via the&amp;nbsp;&lt;/span&gt;&lt;strong&gt;Support&lt;/strong&gt;&lt;span&gt; link in the Zscaler Internet Access or ZIdentity Admin Portal, or call us at&amp;nbsp;&lt;/span&gt;&lt;strong&gt;+1 (408) 752-5885&lt;/strong&gt;&lt;span&gt;. Within the U.S., you can use&amp;nbsp;&lt;/span&gt;&lt;strong&gt;+1 (844) 971-0010&lt;/strong&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Update 3/25/26: Updated verbiage&lt;/li&gt;&lt;/ul&gt;</description>
                <pubDate>Mon, 16 Mar 2026 18:33:56 GMT</pubDate>
                                                                          <eventType>Informational</eventType>
                                                <guid isPermaLink="false">28546 at https://trust.zscaler.com</guid>
        <category domain="https://trust.zscaler.com">Advisory</category>
      </item>
          <item>
        <title>Sitereview Portal Validation Update - zscaler.net, zscalerone.net, zscalertwo.net, zscloud.net, zscalerthree.net, private.zscaler.com, zdxcloud.net, zpatwo.net, app.zsdpc.net, app.eu.zsdpc.net, zpabeta.net, zsdkone.net, zscalerrisk.net, admin.zscaleranalytics.net, zslogin.net</title>
                <link>https://trust.zscaler.com/posts/28536</link>
                                <description>&lt;p&gt;&lt;span&gt;Site review is used by customers and their users to submit URL categorization and review requests to Zscaler. To provide a more secure environment for our ZIA customers, Zscaler is refining how the Site review portal authorizes URL recategorization and review requests. Previously, the portal accepted requests if either the&amp;nbsp;&lt;/span&gt;&lt;strong&gt;Source IP&amp;nbsp;&lt;/strong&gt;&lt;span&gt;or&lt;/span&gt;&lt;strong&gt; the X Forwarded&lt;/strong&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;strong&gt;For&lt;/strong&gt;&lt;span&gt; header belonged to a Zscaler IP address range. As part of a security enhancement, we are removing reliance on the X Forwarded For header. Access will now be restricted to requests originating from a recognized Zscaler Source IP address range or an explicitly whitelisted non Zscaler Source IP.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;What Changed&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Validation Logic Update:&amp;nbsp;&lt;/strong&gt;&lt;span&gt;We are moving from a model that allows either a Zscaler Source IP&amp;nbsp;&lt;/span&gt;&lt;strong&gt;OR&lt;/strong&gt;&lt;span&gt; a Zscaler XFF header to a model that requires a Zscaler Source IP.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Deprecation of XFF Headers:&lt;/strong&gt;&lt;span&gt; The portal will no longer consider the X-Forwarded-For header as a valid identifier for request origin.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Impacted Areas&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Service:&lt;/strong&gt;&lt;span&gt; Sitereview Portal (https://sitereview.zscaler.com/)&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Users:&lt;/strong&gt;&lt;span&gt; ZIA customers performing URL recategorization reviews.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;What is Not Allowed&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;Submissions from non-Zscaler Source IPs that rely solely on the XFF header to identify as a Zscaler customer will no longer be accepted.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;What is Allowed&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;Submissions originating from any valid Zscaler Source IP address.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Submissions from specific customer-owned (non-Zscaler) Source IPs that have been explicitly whitelisted by Zscaler.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Expected Behavior&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;To ensure minimal disruption, Zscaler has already proactively whitelisted known existing non-Zscaler Source IPs used by our customers. We expect most users to experience no change in service.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;For users where submission was previously working but stopped working after a change, they should do the following:&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;Confirm they are accessing Sitereview from a Zscaler IP address (i.e., traffic is egressing through Zscaler).&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;If they must submit from a non-Zscaler egress IP, contact the Zscaler Support Team to request whitelisting (allowlisting) of their non-Zscaler Source IP.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Implementation Timeline&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;This update will be fully implemented after&amp;nbsp;&lt;/span&gt;&lt;strong&gt;April 4, 2026.&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Summary&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Zscaler is updating the request validation logic for the Sitereview portal (sitereview.zscaler.com) to enhance security. Effective&amp;nbsp;&lt;/span&gt;&lt;strong&gt;April 4, 2026&lt;/strong&gt;&lt;span&gt;, the portal will transition to strictly validating the Source IP address for all submissions.&lt;/span&gt;&lt;/p&gt;</description>
                <pubDate>Mon, 16 Mar 2026 14:10:54 GMT</pubDate>
                                                                          <eventType>Informational</eventType>
                                                <guid isPermaLink="false">28536 at https://trust.zscaler.com</guid>
        <category domain="https://trust.zscaler.com">Advisory</category>
      </item>
          <item>
        <title>Commercial Salesforce Security Notification - zscaler.net, zscalerone.net, zscalertwo.net, zscloud.net, zscalerthree.net, private.zscaler.com, zdxcloud.net, zpatwo.net, app.zsdpc.net, app.eu.zsdpc.net, zpabeta.net, zsdkone.net, zscalerrisk.net, admin.zscaleranalytics.net, zslogin.net</title>
                <link>https://trust.zscaler.com/posts/28446</link>
                                <description>&lt;p&gt;&lt;span&gt;On March 10, 2026, Zscaler was made aware of a campaign targeted at the Salesforce Experience Center impacting a large number of Salesforce customers, including Zscaler.&amp;nbsp;Following&amp;nbsp;&lt;/span&gt;&lt;a href=&quot;https://www.salesforce.com/blog/protecting-your-data-essential-actions-to-secure-experience-cloud-guest-user-access/&quot;&gt;&lt;span&gt;guidance from Salesforce&lt;/span&gt;&lt;/a&gt;&lt;span&gt;, Zscaler completed remediation of the incident on March 11, 2026.&lt;/span&gt;&lt;br&gt;&lt;br&gt;&lt;span&gt;Unauthorized access to personal data was limited to the Name and Email Address field from the Commercial Zscaler Community Portal. The scope of the incident was confined to the Zscaler Commercial Salesforce tenant and did not impact the Zscaler Federal Salesforce tenant.&lt;/span&gt;&lt;br&gt;&lt;br&gt;&lt;strong&gt;Zscaler&#039;s products, services and/or underlying systems and infrastructure were not impacted and no sensitive PII was accessed or exposed.&lt;/strong&gt;&lt;/p&gt;</description>
                <pubDate>Fri, 13 Mar 2026 16:29:01 GMT</pubDate>
                                                                          <eventType>Informational</eventType>
                                                <guid isPermaLink="false">28446 at https://trust.zscaler.com</guid>
        <category domain="https://trust.zscaler.com">Advisory</category>
      </item>
          <item>
        <title>Improved Input Validation for User-Editable Text Fields - zscaler.net, zscalerone.net, zscalertwo.net, zscloud.net, zscalerthree.net, private.zscaler.com, zdxcloud.net, zpatwo.net, app.zsdpc.net, app.eu.zsdpc.net, zpabeta.net, zsdkone.net, zscalerrisk.net, admin.zscaleranalytics.net, zslogin.net</title>
                <link>https://trust.zscaler.com/posts/28251</link>
                                <description>&lt;div id=&quot;post_body_wrapper&quot;&gt;&lt;p&gt;&lt;span&gt;We’ve enhanced validation for certain user-editable fields to ensure user-provided values remain plain text and render consistently across the UI (including tables, tooltips, and logs).&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;What Changed&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;ZIA now enforces stricter validation on specific text fields to prevent the use of:&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;HTML / markup&lt;/strong&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;HTML-encoded markup / HTML entities&amp;nbsp;&lt;/strong&gt;&lt;span&gt;(including entity-based representations of special characters or whitespace)&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;span&gt;If disallowed input is detected, the API will reject the request with HTTP 400 (Bad Request).&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Impacted Areas (where this validation applies)&lt;/strong&gt;&lt;/p&gt;&lt;div&gt;&lt;table&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Impacted Areas&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;KB Document&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Webhook names&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://help.zscaler.com/zia/adding-webhook&quot;&gt;https://help.zscaler.com/zia/adding-webhook&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;PAC file names &amp;amp; descriptions&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://help.zscaler.com/zia/about-hosted-pac-files&quot;&gt;https://help.zscaler.com/zia/about-hosted-pac-files&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Static IP descriptions&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://help.zscaler.com/zia/self-provisioning-static-ip-addresses&quot;&gt;https://help.zscaler.com/zia/self-provisioning-static-ip-addresses&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;URLs in URL categories&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://help.zscaler.com/zia/configuring-custom-url-categories&quot;&gt;https://help.zscaler.com/zia/configuring-custom-url-categories&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Extranet names&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://help.zscaler.com/zia/configuring-extranet&quot;&gt;https://help.zscaler.com/zia/configuring-extranet&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Location group names&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://help.zscaler.com/zia/configuring-dynamic-location-groups&quot;&gt;https://help.zscaler.com/zia/configuring-dynamic-location-groups&lt;/a&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;p&gt;&lt;strong&gt;What Is Not Allowed (Rejected with HTTP 400)&lt;/strong&gt;&lt;/p&gt;&lt;ol&gt;&lt;li&gt;&lt;span&gt;HTML / Markup in Input Fields Examples (NOT allowed):&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;poc&amp;lt;a href=&quot;...&quot;&amp;gt;X&amp;lt;/a&amp;gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;&amp;lt;script&amp;gt;alert(1)&amp;lt;/script&amp;gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;&amp;lt;img src=x onerror=alert(1)&amp;gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;&amp;lt;svg onload=alert(1)&amp;gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;HTML-Encoded Markup / HTML Entities Examples (NOT allowed):&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;&amp;amp;lt; , &amp;amp;gt; (encoded &amp;lt; and &amp;gt;)&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;&amp;amp;Tab; (encoded tab)&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;poc&amp;amp;lt;a href=javascript:confirm(document.domain)&amp;amp;gt;X&amp;amp;lt;/a&amp;amp;gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&lt;strong&gt;What Is Allowed&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Plain text values that do not contain HTML markup or HTML entity encodings.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Example (allowed):&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;Webhook for audit notifications - test environment&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Expected Behavior / User Impact&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;Requests containing disallowed content are rejected with HTTP 400 (Bad Request).&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;The object will not be created/updated with the invalid value.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;This ensures user-provided values render predictably in UI locations such as tables, tooltips, and audit logs.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Implementation Timeline&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;Starting from 15 March&lt;/span&gt;&lt;strong&gt;,&lt;/strong&gt;&lt;span&gt; we will begin the update rollout process.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;The rollout will be performed cloud-by-cloud (each production cloud will be updated one by one).&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;By 31 March, the update is expected to be deployed across all production clouds.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Summary&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;As part of a product hardening enhancement, the API now rejects inputs containing HTML markup or HTML entity-encoded markup in select user-editable fields (e.g., webhook names, PAC file metadata, URL category URLs, and naming/description fields). Requests with such values will return HTTP 400.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;For any further information, please feel free to reach out to the Zscaler Support team.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</description>
                <pubDate>Fri, 06 Mar 2026 14:06:00 GMT</pubDate>
                                                                          <eventType>Informational</eventType>
                                                <guid isPermaLink="false">28251 at https://trust.zscaler.com</guid>
        <category domain="https://trust.zscaler.com">Advisory</category>
      </item>
          <item>
        <title>VPN Legacy Application Issue - private.zscaler.com</title>
                <link>https://trust.zscaler.com/posts/28211</link>
                                <description>&lt;p&gt;Zscaler continues to monitor the &lt;a href=&quot;https://trust.zscaler.com/private.zscaler.com/posts/28196&quot;&gt;&lt;strong&gt;previously reported service disruption&lt;/strong&gt;&lt;/a&gt; impacting private.zscaler.com, affecting access to VPN Legacy Applications for a subset of users.&lt;/p&gt;&lt;p&gt;Initial telemetry and early recovery indicators suggested that service behavior had stabilized; however, subsequent monitoring has confirmed that intermittent impact remains for a subset of users. According to the cloud provider’s status page, &lt;strong&gt;two Availability Zones (mec1-az2 and mec1-az3) in the AWS ME-CENTRAL-1 Region&lt;/strong&gt; are currently experiencing impairment, and AWS is actively working toward full restoration.&lt;/p&gt;&lt;p&gt;Customers may refer to the cloud provider’s status page for additional updates related to the underlying infrastructure &lt;a href=&quot;https://health.aws.amazon.com/health/status&quot;&gt;&lt;strong&gt;Status Page&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;.&lt;/strong&gt;&lt;a href=&quot;https://health.aws.amazon.com/health/status&quot;&gt;&lt;span class=&quot;ms-0.5 inline-block align-middle leading-none&quot;&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Zscaler continues close monitoring of the situation and will provide further updates as additional information becomes available or once full service stability is confirmed. Customers requiring assistance or continuing to experience impact are encouraged to contact &lt;strong&gt;Zscaler Support&lt;/strong&gt; for further investigation and guidance.&lt;/p&gt;</description>
                <pubDate>Mon, 02 Mar 2026 20:05:29 GMT</pubDate>
                                                                          <eventType>Informational</eventType>
                                  <customerImpact>Customers may experience issue with ZPA &quot;VPN legacy&quot; services.</customerImpact>
                                <guid isPermaLink="false">28211 at https://trust.zscaler.com</guid>
        <category domain="https://trust.zscaler.com">Advisory</category>
      </item>
          <item>
        <title>VPN Legacy Application Issue - private.zscaler.com</title>
                <link>https://trust.zscaler.com/posts/28196</link>
                                <description>&lt;div id=&quot;post_body_wrapper_main&quot;&gt;&lt;div id=&quot;post_body_wrapper&quot;&gt;&lt;p class=&quot;post_body&quot; id=&quot;post_body&quot;&gt;Zscaler is currently investigating an issue affecting Legacy VPN application services for customers in the UAE region. Initial findings indicate that this disruption is related to an AWS service issue within Availability Zone mec1-az2 in the ME-CENTRAL-1 region.&lt;br&gt;&lt;br&gt;Our operations team is monitoring the situation closely and working toward mitigation. We will provide further updates as more information becomes available.&lt;br&gt;&lt;br&gt;We will continue to provide updates here as the investigation progresses. For detailed updates, please check the Service Status section in your &lt;a href=&quot;https://community.zscaler.com/zenith/s/Guides/aSoPJ0000005aMD0AY/how-to-access-customer-support-portal-csp-and-view-the-service-status-section&quot;&gt;Zscaler customer support portal (CSP).&lt;/a&gt; Status changes and additional details will be posted there as they become available.&lt;/p&gt;&lt;/div&gt;&lt;div class=&quot;latest-update&quot;&gt;&lt;p class=&quot;zs-update&quot;&gt;&lt;strong&gt;Latest Update - &lt;/strong&gt;&lt;span class=&quot;report-time&quot;&gt;Mon, 02 Mar 2026 02:47:13 UTC&lt;/span&gt;&lt;/p&gt;&lt;p&gt;The AWS service disruption has recovered, and Zscaler is considering this issue resolved.&lt;/p&gt;&lt;/div&gt;&lt;div class=&quot;post-updates&quot; id=&quot;post-updates&quot;&gt;&lt;div class=&quot;update-list update-1&quot;&gt;&lt;p class=&quot;zs-update&quot;&gt;Update - &lt;span class=&quot;report-time&quot;&gt;Sun, 01 Mar 2026 17:23:03 UTC&lt;/span&gt;&lt;/p&gt;&lt;p&gt;An issue within AWS was identified, and Zscaler teams are actively working to address and mitigate the problem.&lt;/p&gt;&lt;/div&gt;&lt;div class=&quot;update-list update-2&quot;&gt;&lt;p class=&quot;zs-update&quot;&gt;Update - &lt;span class=&quot;report-time&quot;&gt;Mon, 02 Mar 2026 02:47:13 UTC&lt;/span&gt;&lt;/p&gt;&lt;p&gt;The AWS service disruption has recovered, and Zscaler is considering this issue resolved.&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
                <pubDate>Sun, 01 Mar 2026 17:11:25 GMT</pubDate>
                                                                          <eventType>Informational</eventType>
                                  <customerImpact>Customers may have experienced issue with ZPA &quot;VPN legacy&quot; services.</customerImpact>
                                <guid isPermaLink="false">28196 at https://trust.zscaler.com</guid>
        <category domain="https://trust.zscaler.com">Advisory</category>
      </item>
          <item>
        <title>Middle East Situation and Elevated Monitoring Posture - zscaler.net, zscalerone.net, zscalertwo.net, zscloud.net, zscalerthree.net, private.zscaler.com, zdxcloud.net, zpatwo.net</title>
                <link>https://trust.zscaler.com/posts/28186</link>
                                <description>&lt;p&gt;&lt;span&gt;Zscaler is aware of ongoing geopolitical developments in the Middle East that may impact regional internet connectivity and routing. As part of our standard operational practices, Zscaler is closely monitoring global network conditions and internet infrastructure stability to help maintain continued service reliability for our customers.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;As of February 28, 2026, Zscaler services are operating normally, and we have not observed any impact to platform availability, performance, or security services.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Zscaler continuously monitors external factors that may influence internet routing, regional connectivity, and cybersecurity risk levels. In light of current conditions, we have increased operational monitoring and readiness measures across our global cloud infrastructure as a precautionary step to support service resilience.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Current Service Status&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;All Zscaler services are operating normally.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;As of February 28, 2026, no disruption has been observed Traffic processing, policy enforcement, and security inspection capabilities are functioning as expected.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Operational Readiness&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Zscaler operates a globally distributed cloud platform designed for high availability and continuity. Our operational teams are:&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;Monitoring global internet health, routing stability, and infrastructure conditions&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Monitoring cybersecurity threat activity and indicators relevant to customer environments&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Prepared to take proactive mitigation actions, if required, to maintain service stability and protection&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Customer Guidance&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;No customer action is required at this time.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Customers may continue normal operations. Zscaler will update this advisory on this page and through official communication channels should any service impact occur or additional guidance become necessary.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;</description>
                <pubDate>Sat, 28 Feb 2026 22:11:13 GMT</pubDate>
                                                                          <eventType>Informational</eventType>
                                                <guid isPermaLink="false">28186 at https://trust.zscaler.com</guid>
        <category domain="https://trust.zscaler.com">Advisory</category>
      </item>
          <item>
        <title>Zscaler Client Connector for VDI – Version 1.7 Upgrade Issue - zscaler.net, zscalertwo.net, zscloud.net, zscalerthree.net</title>
                <link>https://trust.zscaler.com/posts/28091</link>
                                <description>&lt;div id=&quot;post_body_wrapper_main&quot;&gt;&lt;div id=&quot;post_body_wrapper_main&quot;&gt;&lt;div id=&quot;post_body_wrapper&quot;&gt;&lt;p&gt;&lt;span&gt;Zscaler is investigating an issue affecting customers who upgraded the Zscaler&lt;/span&gt;&lt;strong&gt; Client Connector for Virtual Desktop Infrastructure (VDI)&lt;/strong&gt;&lt;span&gt; to versions&amp;nbsp;&lt;/span&gt;&lt;strong&gt;1.7.0.4&lt;/strong&gt;, &lt;strong&gt;1.7.0.6&lt;/strong&gt;, or &lt;strong&gt;1.7.0.7&lt;/strong&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Following the upgrade, some VDI instances may remain in an&amp;nbsp;&lt;/span&gt;&lt;strong&gt;“off” state&lt;/strong&gt;&lt;span&gt; due to authentication failures. As a result, impacted VDIs may be unable to establish a connection to the Zscaler service.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Zscaler has identified the issue and validated that reverting to version&amp;nbsp;&lt;/span&gt;&lt;strong&gt;1.6&lt;/strong&gt;&lt;span&gt; restores expected functionality. A permanent fix is currently under validation.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Who is impacted?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;You may be impacted if:&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;You are using&amp;nbsp;&lt;/span&gt;&lt;strong&gt;Zscaler Client Connector (ZCC) for VDI&lt;/strong&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;You upgraded to&amp;nbsp;&lt;/span&gt;&lt;strong&gt;version 1.7.0.4, 1.7.0.6, or 1.7.0.7&lt;/strong&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Your VDI instances are showing an&amp;nbsp;&lt;/span&gt;&lt;strong&gt;“off” state&lt;/strong&gt;&lt;span&gt; and failing authentication&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Customers who remain on&amp;nbsp;version 1.6 or lower are&amp;nbsp;not impacted.&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;What are my next steps?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;If you have upgraded to version &lt;strong&gt;1.7.0.4, 1.7.0.6, or 1.7.0.7&lt;/strong&gt;:&lt;/span&gt;&lt;/p&gt;&lt;ol&gt;&lt;li&gt;&lt;strong&gt;Downgrade Zscaler Client Connector for VDI to version 1.6&lt;/strong&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Validate that the Client Connector Service Status is&amp;nbsp;&lt;/span&gt;&lt;strong&gt;“ON”&lt;/strong&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&lt;span&gt;This downgrade has been validated as a stable interim mitigation. We recommend pausing any additional rollouts of version 1.7 until further notice.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;What if I have more questions?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;If you require assistance with the rollback process or need further clarification, please contact Support.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;post-updates&quot; id=&quot;post-updates&quot;&gt;&lt;div class=&quot;update-list update-1&quot;&gt;&lt;p class=&quot;zs-update&quot;&gt;Update - &lt;span class=&quot;report-time&quot;&gt;Wed, 11 Mar 2026 23:03:48 UTC&lt;/span&gt;&lt;/p&gt;&lt;p&gt;Zscaler has released &lt;a href=&quot;https://help.zscaler.com/cloud-branch-connector/zscaler-client-connector-vdi-release-summary-2026?applicable_category=Windows&amp;amp;applicable_version=1.7.0.10&amp;amp;deployment_date=2026-03-11&amp;amp;id=1538798&quot;&gt;Zscaler Client Connector for VDI version 1.7.0.10&lt;/a&gt;, which includes the fix for the reported issue. By end of day, the 1.7.0.10 image will be made available in the Client Connector App Store within the Client Connector UI, allowing customers to download and deploy the updated image directly. Customers experiencing this issue are advised to upgrade to this version once it becomes available.&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
                <pubDate>Wed, 25 Feb 2026 20:06:14 GMT</pubDate>
                                                                          <eventType>Informational</eventType>
                                                <guid isPermaLink="false">28091 at https://trust.zscaler.com</guid>
        <category domain="https://trust.zscaler.com">Advisory</category>
      </item>
          <item>
        <title>DNS Update for Outbound Email DLP   - zscaler.net, zscalertwo.net, zscalerthree.net</title>
                <link>https://trust.zscaler.com/posts/27856</link>
                                <description>&lt;div id=&quot;post_body_wrapper_main&quot;&gt;&lt;p&gt;&lt;span&gt;Zscaler will be moving outbound Email DLP traffic for the&amp;nbsp;&lt;/span&gt;&lt;strong&gt;securemail.&amp;lt;cloudname&amp;gt;&lt;/strong&gt;&lt;span&gt; domain to previously advertised networks. For details, refer to&lt;/span&gt;&lt;a href=&quot;http://config.zscaler.com/zscaler.net/email-dlp&quot;&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;strong&gt;config.zscaler.com/zscaler.net/email-dlp&lt;/strong&gt;&lt;/a&gt;&lt;span&gt;.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;What is changing?&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;DNS resolution for&amp;nbsp;&lt;/span&gt;&lt;strong&gt;securemail.&amp;lt;cloudname&amp;gt;&lt;/strong&gt;&lt;span&gt; will be updated to point to VIPs that are part of the subnets mentioned in the above article.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Who is impacted?&lt;/strong&gt;&lt;br&gt;&lt;span&gt;This change impacts customers sending outbound Google Workspace (G Suite) email through Zscaler SMTP egress IP ranges who previously updated their configuration to use in.securemail.&amp;lt;cloudname&amp;gt; on&amp;nbsp;&lt;/span&gt;&lt;a href=&quot;https://trust.zscaler.com/zscalertwo.net/posts/27796&quot;&gt;&lt;span&gt;Feb 9&lt;/span&gt;&lt;/a&gt;&lt;span&gt;. These customers may experience email rejection or non-delivery unless the egress IP ranges for securemail.&amp;lt;cloudname&amp;gt; are whitelisted in addition to those already whitelisted for in.securemail.&amp;lt;cloudname&amp;gt;.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;This does not impact customers that have the subnets mentioned in securemail.&amp;lt;cloudname&amp;gt; whitelisted.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Action Required.&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Customers using Google Workspace (G Suite) should whitelist the&amp;nbsp;&lt;/span&gt;&lt;strong&gt;securemail.&amp;lt;cloudname&amp;gt;&lt;/strong&gt;&lt;span&gt; egress IP ranges before the change to ensure continued outbound email delivery when using&amp;nbsp;&lt;/span&gt;&lt;strong&gt;securemail.&amp;lt;cloudname&amp;gt;&lt;/strong&gt;&lt;span&gt;. No action is required if using&amp;nbsp;&lt;/span&gt;&lt;strong&gt;in.securemail.&amp;lt;cloudname&amp;gt;&lt;/strong&gt;&lt;span&gt;. For details, refer to&lt;/span&gt;&lt;a href=&quot;http://config.zscaler.com/zscaler.net/email-dlp&quot;&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;strong&gt;config.zscaler.com/zscaler.net/email-dlp&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;.&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Customers are advised to refer to the Service Status section in their&lt;/span&gt;&lt;a href=&quot;https://community.zscaler.com/zenith/s/Guides/aSoPJ0000005aMD0AY/how-to-access-customer-support-portal-csp-and-view-the-service-status-section&quot;&gt;&lt;span&gt;&amp;nbsp;Zscaler customer support portal (CSP)&lt;/span&gt;&lt;/a&gt;&lt;span&gt; for more details.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;When is the update scheduled?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;The update will be performed during the upcoming maintenance window on a per-cloud basis:&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;ZSN and ZS2 Clouds (all regions):&lt;/strong&gt;&lt;span&gt; Saturday,&amp;nbsp;&lt;/span&gt;&lt;strong&gt;1:00 AM – 6:00 AM UTC&lt;/strong&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;ZS3 Cloud (all regions):&lt;/strong&gt;&lt;span&gt; Sunday,&amp;nbsp;&lt;/span&gt;&lt;strong&gt;1:00 AM – 6:00 AM UTC&lt;/strong&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class=&quot;post-updates&quot; id=&quot;post-updates&quot;&gt;&lt;div class=&quot;update-list update-1&quot;&gt;&lt;p class=&quot;zs-update&quot;&gt;Update - &lt;span class=&quot;report-time&quot;&gt;Mon, 16 Feb 2026 06:53:14 UTC&lt;/span&gt;&lt;/p&gt;&lt;p&gt;This maintenance activity is now completed.&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</description>
                <pubDate>Wed, 11 Feb 2026 07:30:13 GMT</pubDate>
                                                                          <eventType>Informational</eventType>
                                                <guid isPermaLink="false">27856 at https://trust.zscaler.com</guid>
        <category domain="https://trust.zscaler.com">Advisory</category>
      </item>
          <item>
        <title>ZCC Android Defect Update - zscaler.net, zscalerone.net, zscalertwo.net, zscloud.net, zscalerthree.net</title>
                <link>https://trust.zscaler.com/posts/27656</link>
                                <description>&lt;p&gt;&lt;span&gt;Zscaler is aware of a problem with the current 4.1.0.53 Zscaler Client Connector (ZCC) for Android and Android on ChromeOS. On February 2, 2026, Zscaler published the Zscaler Client Connector (ZCC) version 4.1.0.63 release for Android and ChromeOS. Immediately upgrade your Zscaler Client Connector to the latest version for Android in the Google Play Store.&lt;/span&gt;&lt;/p&gt;</description>
                <pubDate>Mon, 02 Feb 2026 18:54:41 GMT</pubDate>
                                                                          <eventType>Informational</eventType>
                                                <guid isPermaLink="false">27656 at https://trust.zscaler.com</guid>
        <category domain="https://trust.zscaler.com">Advisory</category>
      </item>
      </channel>
</rss>
