VYPR

zscaler-mcp-server

by Zscaler

CVEs (1)

  • CVE-2026-59563MedSep 28, 2026
    risk 0.23cvss 4.6epss —

    Zscaler MCP Server versions 0.7.0 and 0.7.1 has an issue where HMAC confirmation tokens were not bound to the target resource identifier, allowing an MCP client or agent to replay a token generated for one resource to affect another resource of the same type. This issue is fixed…