8 updates in the last 7 days/116 total historical

Zscaler updates

Release notes and changelog entries from the vendor feed. Refine with filters, then choose All, Recent, or Limited to focus the list.

Use this Zscaler release notes tracker to review product updates, limited availability notices, and service announcements from official Zscaler feeds in one searchable view.

Updated about 5 hours ago
TimeframeLast 30 Days

Product updates

All updates

Showing 25 of 116 updates
Available
Jul 23, 2026, 03:00 AM EDT
Updated Images for App Connector, Private Service Edge, Private Cloud Controller, and Network Connector
Updated images for Red Hat Enterprise Linux 9 App Connector, Private Service Edge for Private Access (ZPA), Private Cloud Controller, and Network Connector are available for the following: Amazon Web Services (AWS) Google Cloud Platform (GCP) Microsoft Azure Nutanix AHV for App Connector and Private Service Edge VMware for App Connector, Private Service Edge, and Private Cloud Controller These image updates include a 4 GB boot partition that exceeds Red Hat's recommendations to help support seamless OS updates. To learn more, see: App Connector Software by Platform Private Service Edge Software by Platform Private Cloud Controller Software by Platform Network Connector Software by Platform
ZPA (Private Access)zpatwo.net
Available
Jul 23, 2026, 03:00 AM EDT
Updated Images for App Connector, Private Service Edge, Private Cloud Controller, and Network Connector
Updated images for Red Hat Enterprise Linux 9 App Connector, Private Service Edge for Private Access (ZPA), Private Cloud Controller, and Network Connector are available for the following: Amazon Web Services (AWS) Google Cloud Platform (GCP) Microsoft Azure Nutanix AHV for App Connector and Private Service Edge VMware for App Connector, Private Service Edge, and Private Cloud Controller These image updates include a 4 GB boot partition that exceeds Red Hat's recommendations to help support seamless OS updates. To learn more, see: App Connector Software by Platform Private Service Edge Software by Platform Private Cloud Controller Software by Platform Network Connector Software by Platform
ZPA (Private Access)private.zscaler.com
Available
Jul 21, 2026, 03:00 AM EDT
Zero Trust Branch 8.0.8P5a
Resolved Issues The following issues were resolved: Fixed an issue where log retention enhancements, introduced by certain gateway upgrades in the 8.0.8P5 release, could cause the log upload step to fail silently post-upgrade on certain systems. The fix updates the log upload mechanism, ensuring rotated component logs are reliably uploaded. Fixed an issue where, on high availability (HA) standby gateways, intermittent changes in the standby DROP policy that were preventing border gateway protocol (BGP) peering until a switchover were causing the BGP neighbor state on routed tunnels to flap. The fix streamlines the DROP policy enforcement to prevent policy flaps and peering state bouncing. Fixed an issue where after certain service reboots, LAN-to-Private Access (ZPA) traffic could intermittently fail due to a missing default Private Access route or rule path on the Zero Trust Branch gateway. The fix enhances the periodic self-healing functionality to verify and restore the default Private Access default route, ensuring that the route is always present in the Private Access route table. Fixed an issue where some policy-based routing (PBR) rules were not programmed, which resulted in incorrect routing and forwarding policy behavior. The fix enhances PBR reconciliation, strengthening the resiliency of rules programming. Fixed an issue where PBR rules that match on destination app segments could fail to install on Zero Trust Branch appliances, especially on those where referenced app segments were missing, which resulted in routing issues for matching user traffic. The fix updates how this issue is handled in the PBR retry loop to ensure PBR rules are properly reconciled and installed. Fixed an issue where a gateway upgrade process incorrectly cleared the required web proxy configuration for certain system services, which resulted in syslog and telemetry upload mechanism failures. The fix ensures that the gateway upgrade process correctly restores the web proxy configuration for all system services. Fixed an issue where Zero Trust Branch could incorrectly provide 8.8.8.8 as the DNS server to endpoints instead of the VLAN-configured DNS on DHCPINFORM packets. The fix ensures that Zero Trust Branch now replies with the configured DNS server on DHCPINFORM packets. Fixed an issue where after a reboot, a timing issue sometimes caused the Open Shortest Path First (OSPF) configuration to apply before interfaces were fully operational, which prevented the configuration from being correctly applied and intermittently caused OSPF adjacency failures in Virtual Routing and Forwarding deployments. The fix updates the configuration reconciliation logic to handle these circumstances and ensures the OSPF configuration is properly applied on reboot.
Zero Trust Branch
Available
Jul 21, 2026, 03:00 AM EDT
Zero Trust Branch 8.1.2
New Features and Enhancements The following enhancements were added as part of the Zero Trust Branch 8.1.2 release: DTLS-Based Internet & SaaS Connectivity Support and Location Enhancements Added support for DTLS-based connectivity to Internet & SaaS, enabling secure, higher-throughput tunnels with automatic fallback to TLS when DTLS is unavailable. This update aligns new Zero Trust Branch deployments with Zero Trust Branch groups and sublocations to simplify branch onboarding while providing greater flexibility for transport options. For existing sites, you can create a new location that supports Zscaler Tunnel (Z-Tunnel) and associate it with the site. You can enable Zscaler Tunnel (Z-Tunnel) for a site on the Connectivity tab. See image. Use DTLS tunnels in Traffic Forwarding policy rules that are currently configured to use IPSec tunnels. The following location enhancements were added: Support for location templates while adding new sites. This applies only for new deployments. Existing sites and appliances cannot be switched to new location types without full redeployment. See image. Beginning with version 8.1.2, the new locations created for Zero Trust Branch sites would create corresponding Internet & SaaS locations with VPN credentials with the Workload type. For these sites, you can switch from IPSec tunnel to Zscaler Tunnel (Z-Tunnel). Custom Internet & SaaS (ZIA) Gateway Objects Support You can define custom ZIA Gateway objects to steer traffic to specific gateways for policy enforcement, performance, routing, regional compliance requirements, configure primary and secondary gateways with failover for resiliency, and pin sites to a gateway for troubleshooting. See image. Support for Hub Deployment in Microsoft Azure and Amazon Web Services (AWS) Added support for deploying a hub in AWS and Azure, with downloadable ISO, Virtual Hard Disk (VHD), and Open Virtual Appliance (OVA) images, helping standardize and accelerate cloud-based deployments while reducing manual setup. For AWS, you must download the OVA image and convert it to Amazon Machine Image (AMI) using the AWS CLI. You can access these images from Service Portal > Zero Trust Branch > Settings > ZTB Images. Support for China Deployments Added support for China deployments in Zero Trust Branch, enabling consistent Zero Trust connectivity for branches in China, including support for bootstrap, provisioning, and back-end communications, custom Internet & SaaS (ZIA) gateway selection, connectivity to China public Internet & SaaS and Private Access data centers, and support for partner-hosted Private Access brokers. Support for Internet Group Management Protocol (IGMP) Querier Added support for the IGMP Querier on Layer 2 VLANs, enabling the Zero Trust Branch appliance to periodically transmit IGMP Query messages and maintain multicast group membership for more reliable multicast traffic across VLANs. See image. The IGMP Querier supports IGMPv2 and IGMPv3. Ensure that the appropriate version is configured for your environment. Private Access (ZPA) Log Level Configuration Added support for configuring ZPA log levels on Zero Trust Branch appliances. See image. ZPA Logs must be enabled only for active appliances. Management Interface Enhancement Added support for both in-band and out-of-band management interfaces in Zero Trust Branch to provide stronger management-plane isolation. Admins can configure management access using a loopback interface within the main routing domain or a dedicated physical interface in a separate management Virtual Routing and Forwarding (VRF) instance for isolated access. See image. Support for Link Layer Discovery Protocol (LLDP) Added support for LLDP on Zero Trust Branch interfaces to discover neighboring devices and display device information, including device identity, port descriptions, OS versions, and management IP addresses, helping simplify troubleshooting and validate physical connectivity. See image. LLDP is enabled by default on LAN, HA, and management interfaces. You can enable it manually on other interfaces as needed. LLDP works only when the out-of-band management interface is configured. Border Gateway Protocol (BGP) Route Filtering Added support for BGP prefix filtering using import and export maps to control inbound and outbound route advertisements. See image. The route map filters for both import and export options allow filtering by including or excluding IP prefixes. See image. The following limitations apply: Network object groups with FQDN members cannot be used for route filtering. Only one export and one import route-map is supported per BGP peer or neighbor. Only user-defined network object groups can be used in route-maps. Route matching supports only IP-based prefix lists. AS-PATH, MED, and Communities are not supported. System and WAN Health Monitoring Added support for real-time and historical monitoring of tunnel, connectivity, system and WAN health, including appliance resource utilization, WAN bandwidth usage, interface state changes, and WAN performance metrics. Admins can monitor CPU, memory, disk usage, interface status, throughput, latency, jitter, packet loss, WANMon scores, and timestamped interface Up/Down events, and they can run on-demand WAN speed tests to validate link performance and troubleshoot connectivity issues. See image. Weight-Based High Availability (HA) Added support for weighted interface tracking in Zero Trust Branch HA deployments to enable weight-based failover decisions and reduce unnecessary failovers during transient WAN, interface, or service failures. The weigh-based failover tracks the following components: Category Components Services agn-poller securedhcp-relay agn-dhcp-uploader agn-state-monitor Processes zcc-client Containers vyos_container policy_container dnsproxy_container zeek Interface Enhancements The following enhancements were made to improve interface configuration, status visibility, and connectivity validation: Added interface utilization metrics, throughput calculations, refresh controls, and administrative status management to the Interfaces page. See image. Added support to modify speed from the UI. This setting allows manual configuration of the interface speed using a drop-down menu with the following options: GE Interface: Auto (default), 100M, 1G XE Interface: Auto (default), 100M, 1G, 10G Desired Duplex: This feature is provided to support connectivity with legacy equipment requiring specific duplex types. A drop-down menu offers the following options: Auto (default), Half, Full. Desired MTU (Maximum Transmission Unit): A number input field where the maximum permissible value is 9000. Admin Status: This control physically enables (Admin Up) or disables (Admin Down) the interface. Changing the administrative status also reflects in the link status. An Up (default) / Down toggle button is implemented for this purpose. See image. Appliance Admin Console Added Appliance Admin Console, a command-line interface, for appliance management and troubleshooting, providing configuration (starts with config ), operational (starts with run ), and status or show (starts with show ) commands with improved usability, mandatory password changes on first login, and audit logging to help prevent unintended shell access. See image. Site Health Monitoring The site Overview page includes the following widgets: Connectivity Health: Shows health status of Internet & SaaS IPSec tunnels. It also includes an option to probe Private Access endpoints to check if the endpoints are reachable from the site. Critical Services Health: Shows the status of various components of Zero Trust Branch. See image. Low Bandwidth Mode Support Added low bandwidth mode for Zero Trust Branch appliances running version 8.1.2 or later to optimize performance in bandwidth-constrained environments. See image. The following limitations apply when low bandwidth mode is enabled: Asset Discovery is disabled. Configuration updates can take up to an hour if the configuration control channel is unavailable. Requires manual configuration from Zscaler Support for a Private Access setting configuration. DHCP Enhancements Address Conflict Detection Added a check to detect duplicate IP address conflicts before assigning DHCP leases, improving reliability and preventing IP address conflicts in the network. See image. Support for DHCP Profiles (Per-VLAN) Option Zero Trust Branch supports granular control over DHCP configurations with per-VLAN DHCP options, simplifying multi-VLAN deployments by allowing you to configure DHCP options on a per-VLAN basis for enhanced security and operational flexibility. This enhancement allows you to assign different DHCP options to different VLANs, ensuring that corporate devices receive necessary network information while guest devices are isolated from sensitive internal services. Each DHCP profile can be configured for either a DHCP Server (with custom options) or a DHCP Relay. You can create a DHCP profile and associate it with a VLAN. See image. Support for Zscaler Branch Connector Groups Added support to associate Branch Connector groups with Zero Trust Branch sites for consistent policy application in Internet & SaaS and Private Access. Support for Internet & SaaS and Private Access Sublocations Zero Trust Branch syncs with Zscaler Central Authority (CA) for obtaining sublocation definitions and applies labels to traffic origination from those locations within networks managed by Zero Trust Branch. This ensures Private Access differentiates traffic from network segments and applies policies for sublocation traffic originating from a Zero Trust Branch network. See image. ENTITY-MIB Support Added support for ENTITY-MIB for SNMP, which allows capturing host-level metrics, such as CPU and disk usage, through a host-based SNMP proxy service. UI Enhancements The following UI enhancements were added: A new field (Comment) to support adding comments while configuring static routes. See image. Support for uploading networks and MAC addresses in bulk via CSV files to create objects. See image. Option to clone forwarding policies. See image. Option to filter security policies based on the Ransomware Kill Switch indicators. See image. Support to view (read-only) system default groups. See image. An Appliance Inventory page that automatically populates appliance hardware serial numbers and provides visibility into deployed devices and their status, simplifying appliance registration for Zero Touch Provisioning and improving operational oversight. See image. Resolved Issues The following issues were resolved: Fixed an issue where failover was not triggered when the primary WAN next hop is unreachable and no distribution method was configured. Fixed an issue where certain Zscaler IP addresses were not referenced in default routing policies.
Zero Trust Branch
Limited Availability
Jul 20, 2026, 03:00 AM EDT
Business-to-Business (B2B) Federation
B2B Federation supports secure sharing of resources between business partners, and allows organizations to establish trusted cross-partner relationships. You can create Partner Federation requests, manage incoming and outgoing requests, and manage federated partners that have established trust. After establishing trust between two organizations, admins can federate application segments to partners and enforce Zero Trust granular controls for shared resources and users. The same functionality is supported via the Private Access (ZPA) cloud service API. See image. To learn more, see: Understanding Business-to-Business (B2B) Federation About Federated Partners About Pending Requests for Partners Configuring Business-to-Business Federation Federating Partners Using API Federating Applications Using API Obtaining Access Policy Details for Federating Applications Using API
ZPA (Private Access)zpatwo.net
Limited Availability
Jul 20, 2026, 03:00 AM EDT
Step-Up Authentication for Privileged Remote Access
Step-up authentication is supported for Privileged Remote Access (PRA) and enhances security by only allowing access to applications after users complete additional authentication. Conditional access is supported for step-up authentication in the Zscaler Admin Console. To learn more, see Configuring Access Policies and Understanding Step-Up Authentication .
ZPA (Private Access)zpatwo.net
Limited Availability
Jul 20, 2026, 03:00 AM EDT
Business-to-Business (B2B) Federation
B2B Federation supports secure sharing of resources between business partners, and allows organizations to establish trusted cross-partner relationships. You can create Partner Federation requests, manage incoming and outgoing requests, and manage federated partners that have established trust. After establishing trust between two organizations, admins can federate application segments to partners and enforce Zero Trust granular controls for shared resources and users. The same functionality is supported via the Private Access (ZPA) cloud service API. See image. To learn more, see: Understanding Business-to-Business (B2B) Federation About Federated Partners About Pending Requests for Partners Configuring Business-to-Business Federation Federating Partners Using API Federating Applications Using API Obtaining Access Policy Details for Federating Applications Using API
ZPA (Private Access)private.zscaler.com
Limited Availability
Jul 20, 2026, 03:00 AM EDT
Step-Up Authentication for Privileged Remote Access
Step-up authentication is supported for Privileged Remote Access (PRA) and enhances security by only allowing access to applications after users complete additional authentication. Conditional access is supported for step-up authentication in the Zscaler Admin Console. To learn more, see Configuring Access Policies and Understanding Step-Up Authentication .
ZPA (Private Access)private.zscaler.com
Available
Jul 17, 2026, 03:00 AM EDT
Zscaler Admin Console 4.5.5
Fixes a pagination issue that caused incorrect user search results on the Enrolled Devices page. Fixes a timeout issue that caused the file download of Device Details on the Enrolled Devices page to fail. Fixes an issue where the Protocol drop-down menu on the Add Application window in Experience Center was blank when adding a custom IP-based application bypass . Fixes a sync issue where users added to user groups that were already assigned Private Access service entitlement didn’t receive access to Private Access even after clicking Update Policy.
Client Connector Portalzscalertwo.net
Available
Jul 17, 2026, 03:00 AM EDT
New Client Certificate for Virtual Instances
A new client certificate that offers improved security has been added for the following Zscaler virtual instances: DLP Index Tool Nanolog Streaming Service (NSS) NSS Collector Virtual Service Edge Zscaler Incident Receiver Zscaler Authentication Bridge (ZAB) For each, you can access the New Client Certificate window, which contains a download link for the necessary configuration file, and a section for uploading provisioning blob data. To learn more, see: About the Index Tool About Virtual Service Edges for Internet & SaaS About NSS Servers About NSS Collector Servers About Zscaler Incident Receiver About the Zscaler Authentication Bridge
ZIA (Internet Access)zscalerone.net
Available
Jul 17, 2026, 03:00 AM EDT
Partial Configuration Handling Mechanism
In Advanced Settings, a new Behavior When Partial Configuration Available setting is added to define how security policies are enforced during transient network disruptions that can rarely result in a Service Edge for Internet & SaaS (ZIA) operating with incomplete or cached tenant, user, or location configurations. The Behavior When Partial Configuration Available setting provides three different modes of control to balance security and connectivity during such rare disconnects: A Service Edge having only partial configurations is extremely unlikely under normal operating conditions. If this condition does occur, which is extremely rare to never, the selected mode is activated. Fail Open: If complete configurations are not available, policy evaluation is skipped and the traffic is allowed to pass through. This is the default mode and ensures maximum connectivity. Fail Close: Prioritizes strict security by blocking traffic unless a complete configuration is available to apply. This mode should be selected for the strictest application of policy rules on every session at the risk of some sessions being blocked occasionally. Best Effort Policies: Applies the most specific policy rules available by falling back to a predefined user (Miscellaneous Unauthenticated Transactions) or location (a new Org Default location is added), or both. This mode is intended to balance maximum connectivity with strict blocking, ensuring that policies are still applied in rare cases when only a partial configuration is available. See image. The selected mode applies to both secure web gateway and firewall traffic. The policy application based on the selected mode is recorded in Firewall and Web logs. In the Best Effort Policies mode, transactions that use a partial configuration for policy enforcement are distinguished in Web logs using a new Configuration field set to the Partial value (all other transactions are indicated by the Full value). The Configuration field is also available as a filter in Web logs.
ZIA (Internet Access)zscalerone.net
Available
Jul 16, 2026, 03:00 AM EDT
Update App Connector Groups for Where Your Apps Are Served
You can edit App Connector groups on the Where are my apps being served from? page to resolve unknown app hosting and location details. See image. To learn more, see Viewing Where Your Apps Are Served .
ZPA (Private Access)zpatwo.net
Available
Jul 16, 2026, 03:00 AM EDT
Update App Connector Groups for Where Your Apps Are Served
You can edit App Connector groups on the Where are my apps being served from? page to resolve unknown app hosting and location details. See image. To learn more, see Viewing Where Your Apps Are Served .
ZPA (Private Access)private.zscaler.com
Available
Jul 16, 2026, 03:00 AM EDT
Real User Monitoring's Browser Extension Version 0.1.37
Zscaler released Browser Extension version 0.1.37 of Real User Monitoring (RUM) to include the following: Adds additional RUM metrics that include remote address, transfer size, and request header content length. Updates the message when collecting RUM metrics. Fixes an issue where unnecessary logs are displayed in the browser console. Enhances and extends log limitations. Enhances security from extension to application. To update to the latest version, refer to: Chrome Web Store - Zscaler Real User Monitoring (RUM) Microsoft Edge Add-ons - Zscaler Real Time User Monitoring
ZDX (Digital Experience)zdxcloud.net
Available
Jul 15, 2026, 03:00 AM EDT
Virtual Service Edges Supported for Nutanix
Virtual Service Edge configuration is supported on the Nutanix platform. You can download the Nutanix VM image on the Virtual Service Edges page. To learn more, see Configuring Virtual Service Edges for Internet & SaaS: Nutanix .
ZIA (Internet Access)zscalerthree.net
Available
Jul 15, 2026, 03:00 AM EDT
Zscaler Client Connector 4.5.2.334 Enhancements and Fixes
Updates the VPN Gateway Bypass to optionally not bypass subdomains for FQDNs. To learn more, see Bypassing FQDN Subdomains for VPN Gateway Bypass . Fixes an issue where Run Zscaler Diagnostics on Zscaler Client Connector never completed or failed to start because the tool incorrectly detected another running instance and prompted for profile installation input during a UI-initiated run. Fixes an issue where users lost internet connectivity because Internet & SaaS in Transparent Proxy-based Traffic Interception mode entered a tunnel restart rate-limited state and required a device restart to recover. Fixes an issue where Zscaler Client Connector stopped consuming network changes after running for some time. Fixes an issue where End User Notifications randomly stopped appearing for Data Loss Prevention (DLP) transactions until the Zscaler Client Connector service was restarted. Fixes an issue where Zscaler Client Connector did not update Private Access with current posture results, causing access failures due to stale unverified posture status. Fixes an issue where Internet & SaaS remained disabled despite valid entitlement and policy enforcement until Restart Service selected or Zscaler Client Connector was restarted. Fixes an issue where overlapping Private Access auto-reauthentication flows caused SAML SP PKCE mismatches and displayed an Invalid Response Received error. Fixes an issue where Zscaler Client Connector returned a bad request error during Private Access reauthentication for authentication service for end user migration pilot users. Fixes an issue where Private Access reauthentication did not trigger for migrated users after session expiry, leaving access broken until Zscaler Client Connector was relaunched. Fixes an issue where Zscaler Client Connector relied on an unreliable opendirectoryd lookup to detect Active Directory (AD) binding, which caused empty Private Access client-to-client FQDN registration data to be sent when the device was actually AD bound. Fixes an issue where Private Access experienced connectivity failures after Zscaler Client Connector upgrades during device startup or resume from sleep, and provided the Mobile Device Management (MDM) flag disableFirewallHealthCheck to ignore the results of route-based tunnel echo health checks. Fixes an issue where posture checks weren’t evaluated correctly for a partner if the domain of the partner tenant is on a different cloud than the main tenant. Fixes an issue where dedicated IP forwarding traffic was not consistently captured by Internet & SaaS when users switched networks or toggled Wi-Fi, which caused applications to use a non-allowlisted source IP until Zscaler Client Connector was restarted.
Client Connector
Available
Jul 15, 2026, 03:00 AM EDT
Zscaler Client Connector 4.7.0.321 Enhancements and Fixes
Updates the VPN Gateway Bypass to optionally not bypass subdomains for FQDNs. To learn more, see Bypassing FQDN Subdomains for VPN Gateway Bypass . Fixes an issue where Run Zscaler Diagnostics on Zscaler Client Connector never completed or failed to start because the tool incorrectly detected another running instance and prompted for profile installation input during a UI-initiated run. Fixes an issue where users lost internet connectivity because Internet & SaaS in Transparent Proxy-based Traffic Interception mode entered a tunnel restart rate-limited state and required a device restart to recover. Fixes an issue where Zscaler Client Connector stopped consuming network changes after running for some time. Fixes an issue where End User Notifications randomly stopped appearing for Data Loss Prevention (DLP) transactions until the Zscaler Client Connector service was restarted. Fixes an issue where Zscaler Client Connector did not update Private Access with current posture results, causing access failures due to stale unverified posture status. Fixes an issue where Internet & SaaS remained disabled despite valid entitlement and policy enforcement until Restart Service selected or Zscaler Client Connector was restarted. Fixes an issue where overlapping Private Access auto-reauthentication flows caused SAML SP PKCE mismatches and displayed an Invalid Response Received error. Fixes an issue where Zscaler Client Connector returned a bad request error during Private Access reauthentication for authentication service for end user migration pilot users. Fixes an issue where Private Access reauthentication did not trigger for migrated users after session expiry, leaving access broken until Zscaler Client Connector was relaunched. Fixes an issue where Zscaler Client Connector relied on an unreliable opendirectoryd lookup to detect Active Directory (AD) binding, which caused empty Private Access client-to-client FQDN registration data to be sent when the device was actually AD bound. Fixes an issue where Private Access experienced connectivity failures after Zscaler Client Connector upgrades during device startup or resume from sleep, and provided the Mobile Device Management (MDM) flag disableFirewallHealthCheck to ignore the results of route-based tunnel echo health checks. Fixes an issue where posture checks weren’t evaluated correctly for a partner if the domain of the partner tenant is on a different cloud than the main tenant. Fixes an issue where dedicated IP forwarding traffic was not consistently captured by Internet & SaaS when users switched networks or toggled Wi-Fi, which caused applications to use a non-allowlisted source IP until Zscaler Client Connector was restarted.
Client Connector
Available
Jul 15, 2026, 03:00 AM EDT
Zscaler Client Connector 4.8.0.221 Enhancements and Fixes
Updates the VPN Gateway Bypass to optionally not bypass subdomains for FQDNs. To learn more, see Bypassing FQDN Subdomains for VPN Gateway Bypass . Fixes an issue where users lost internet connectivity because Internet & SaaS in Transparent Proxy-based Traffic Interception mode entered a tunnel restart rate-limited state and required a device restart to recover. Fixes an issue where Zscaler Client Connector stopped consuming network changes after running for some time. Fixes an issue where End User Notifications randomly stopped appearing for Data Loss Prevention (DLP) transactions until the Zscaler Client Connector service was restarted. Fixes an issue where Zscaler Client Connector did not update Private Access with current posture results, causing access failures due to stale unverified posture status. Fixes an issue where Internet & SaaS remained disabled despite valid entitlement and policy enforcement until Restart Service selected or Zscaler Client Connector was restarted. Fixes an issue where overlapping Private Access auto-reauthentication flows caused SAML SP PKCE mismatches and displayed an Invalid Response Received error. Fixes an issue where Zscaler Client Connector returned a bad request error during Private Access reauthentication for authentication service for end user migration pilot users. Fixes an issue where Private Access reauthentication did not trigger for migrated users after session expiry, leaving access broken until Zscaler Client Connector was relaunched. Fixes an issue where Zscaler Client Connector relied on an unreliable opendirectoryd lookup to detect Active Directory (AD) binding, which caused empty Private Access client-to-client FQDN registration data to be sent when the device was actually AD bound. Fixes an issue where Private Access experienced connectivity failures after Zscaler Client Connector upgrades during device startup or resume from sleep, and provided the Mobile Device Management (MDM) flag disableFirewallHealthCheck to ignore the results of route-based tunnel echo health checks. Fixes an issue where posture checks weren’t evaluated correctly for a partner if the domain of the partner tenant is on a different cloud than the main tenant. Fixes an issue where dedicated IP forwarding traffic was not consistently captured by Internet & SaaS when users switched networks or toggled Wi-Fi, which caused applications to use a non-allowlisted source IP until Zscaler Client Connector was restarted.
Client Connector
Available
Jul 15, 2026, 03:00 AM EDT
Support for Creating Tenants in India Region
Authentication Service now provides support for creating tenants in the India region, in addition to the United States and European Union. To enable connectivity with Authentication Service, make sure to allowlist the required IP ranges in your environment. To learn more, see Authentication Service Logs .
ZIdentityzslogin.net
Available
Jul 14, 2026, 03:00 AM EDT
journalctl Support for Remote Troubleshooting
Private Access (ZPA) supports the journalctl command for App Connectors, Private Service Edges, Private Cloud Controllers, and Network Connectors to collect service logs or full system logs for remote troubleshooting. See image. To learn more, see Accessing and Viewing Support Information or Configuring VPN Diagnostic Sessions .
ZPA (Private Access)zpatwo.net
Available
Jul 14, 2026, 03:00 AM EDT
Virtual Service Edges Supported for Nutanix
Virtual Service Edge configuration is supported on the Nutanix platform. You can download the Nutanix VM image on the Virtual Service Edges page. To learn more, see Configuring Virtual Service Edges for Internet & SaaS: Nutanix .
ZIA (Internet Access)zscalertwo.net
Available
Jul 14, 2026, 03:00 AM EDT
journalctl Support for Remote Troubleshooting
Private Access (ZPA) supports the journalctl command for App Connectors, Private Service Edges, Private Cloud Controllers, and Network Connectors to collect service logs or full system logs for remote troubleshooting. See image. To learn more, see Accessing and Viewing Support Information or Configuring VPN Diagnostic Sessions .
ZPA (Private Access)private.zscaler.com
Available
Jul 14, 2026, 03:00 AM EDT
Virtual Service Edges Supported for Nutanix
Virtual Service Edge configuration is supported on the Nutanix platform. You can download the Nutanix VM image on the Virtual Service Edges page. To learn more, see Configuring Virtual Service Edges for Internet & SaaS: Nutanix .
ZIA (Internet Access)zscloud.net
Available
Jul 13, 2026, 03:00 AM EDT
L4 Ingress Support for Cloud & Branch Connector
Cloud & Branch Connector provides Source Network Address Translation (SNAT) and Destination Network Address Translation (DNAT) capabilities in AWS, Azure, and GCP. To learn more, see About Traffic Forwarding and Configuring Traffic Forwarding Rules . Cloud & Branch Connector supports Azure Gateway Load Balancer via Terraform.
Cloud & Branch Connectorzscalertwo.net
Limited Availability
Jul 13, 2026, 03:00 AM EDT
Amazon Web Services Support in Zscaler Client Connector for VDI
Support for Amazon Web Services (AWS), Citrix, and Windows servers in AWS using Zscaler Client Connector for VDI is available for Cloud Connector. To learn more, see What Is Zscaler Client Connector for VDI? and Customizing Zscaler Client Connector for VDI with Install Options for MSI .
Cloud & Branch Connectorzscalerthree.net

Data access

Unlock more updates for Zscaler

You're seeing 116 updates from the last 7 days without signing in.

Public session

Public
Your view
116 updates

Next step: Free - 7 days history and full feed tools. No card required to start.

What you can unlock

Higher tiers unlock more history and more rows.

  • Recommended next step

    Standard

    30 days · wider access

    Wider window

  • Pro

    90 days · wider access

    Wider window

  • Enterprise

    Unlimited · wider access

    Wider window

Timeframe

Items older than this window stay hidden unless you widen the range or choose All time.