Blog Zscaler

Recevez les dernières mises à jour du blog de Zscaler dans votre boîte de réception

Products & Solutions

What’s New in GovCloud: August 2026 Zscaler Product Updates

image

Product releases move fast, and carving out time to review what's changed across multiple platforms is rarely at the top of anyone's to-do list. Here is a curated roundup of notable Zscaler GovCloud updates from August, with quick context and scan-friendly takeaways you can share across security, network, and operations teams. Highlights include WebSocket traffic inspection in ZIA, new ThreatParse detection rules for actively exploited CVEs in Deception, BGP route filtering and DNS-over-HTTPS support in Zero Trust Branch, and customizable password policies in the Authentication Service.

Zscaler Internet Access (ZIA)

Zscaler Internet Access (ZIA) is Zscaler's secure internet and SaaS access service, providing policy-based protection and visibility for users wherever they work. For many federal environments, ZIA is central to enforcing acceptable use, protecting sensitive data, and maintaining consistent security controls across a distributed workforce.

This month's ZIA updates expand inspection coverage to WebSocket traffic, introduce resilience controls for partial configuration scenarios, and add new search filters to simplify management of large firewall rule sets.

Highlights

  • Partial Configuration Handling Mechanism: A new "Behavior When Partial Configuration Available" setting lets admins choose how policy is enforced if a Service Edge is operating on incomplete or cached tenant/user/location data. Options include Fail Open, Fail Close, or Best Effort Policies, giving teams control over the tradeoff between availability and security posture during edge cases.
  • WebSocket Inspection Enhancements: ZIA now inspects bidirectional WebSocket traffic for supported content, extending security and data-protection controls to these communications. This closes a visibility gap for applications that rely on persistent WebSocket connections.
  • New Search Filters for Firewall Filtering Policy Rules: New filters have been added to the Firewall Filtering Policy page, including Rule Status, Network/Application Service Groups, Source/Destination Country, and IPv6 Groups. These make large rule sets easier to search and manage at scale.

For full release notes: https://help.zscaler.us/zia/release-upgrade-summary-2026

Zscaler Private Access (ZPA)

Zscaler Private Access (ZPA) provides secure, zero trust connectivity between users and private applications without exposing those applications to the internet. It helps organizations reduce attack surface while improving access experience, which is especially important for distributed users, mission partners, and hybrid work environments common across federal agencies.

This month's ZPA updates deliver a recommended Manager software release and security-fix updates for both Private Service Edge and Private Cloud Controller.

Highlights

  • Manager Software Updates: Released updated App Connector, Private Service Edge, and Private Cloud Controller RPM packages for RHEL 8.x/9.x (Manager software version 26.54.6). Packages are downloadable from the Zscaler repository.
  • Private Service Edge Version 26.54.6: A security-fix update for Private Service Edge, applied per your configured software update schedule.
  • Private Cloud Controller Version 26.54.6: A security-fix update for Private Cloud Controller, applied per your configured software update schedule.

For full release notes: https://help.zscaler.us/zpa/release-upgrade-summary-2026

Zscaler Client Connector

Zscaler Client Connector is the unified endpoint agent that steers traffic to ZIA, ZPA, and ZDX services. It ensures consistent policy enforcement regardless of where users connect from, which is critical for agencies supporting remote and hybrid workforces.

This month's update addresses several Admin Console usability and functionality issues.

Highlights

  • Zscaler Admin Console 4.5.5: This release fixes device-search pagination, a device-details export timeout, a blank protocol dropdown in Experience Center, and a policy-sync issue affecting Private Access entitlement assignment. These fixes improve day-to-day administrative workflows and entitlement accuracy.

For full release notes: https://help.zscaler.us/client-connector/release-upgrade-summary-2026

Zero Trust Branch

Zscaler Zero Trust Branch helps modernize branch security and connectivity by bringing zero trust principles to branch offices, remote sites, and OT/IoT environments, reducing reliance on legacy appliances while maintaining consistent policy enforcement.

This month's Zero Trust Branch update introduces BGP route filtering, DNS-over-HTTPS support, and FIPS enablement improvements, continuing to strengthen both routing flexibility and compliance alignment.

Highlights

  • Zero Trust Branch 8.2.1P1: This release adds BGP route filtering with import/export maps, DNS-over-HTTPS configuration for Hub sites and custom DoH endpoints, FIPS enablement with NTP fixes, additional BGP policy filters, and improved App Connector auto-recovery status reporting. These enhancements give network teams more control over routing policy and encrypted DNS resolution at the branch.

For full release notes: https://help.zscaler.us/zero-trust-branch/release-upgrade-summary-2026

Zscaler Deception

Zscaler Deception deploys decoys and lures across environments to detect lateral movement, credential theft, and attacker reconnaissance. For federal organizations, deception adds an active defense layer that can identify adversary activity early in the kill chain without relying solely on signature-based detection.

This month's Deception updates deliver new detection rules for actively exploited vulnerabilities, enhanced network fingerprinting in event logs, and an expanded decoy dataset for network appliances.

Highlights

  • New ThreatParse Rules: Added detection rules for several actively relevant CVEs, including unauthenticated RCE in Langflow, an unauthenticated file-write flaw in Splunk, a PHP code-injection issue in Everest Forms Pro, and vulnerabilities affecting Fortinet FortiClient EMS, Ivanti Endpoint Manager, Ivanti Sentry, and Cisco Secure Firewall Management Center. These rules help identify adversaries leveraging current exploit techniques.
  • Admin Portal Enhancements: Event logs now support JA3/JA4 network fingerprints for web decoys, and web server banners for network and Threat Intelligence decoys were updated for improved accuracy. This strengthens forensic context and decoy realism.
  • New Datasets: Added a new high-interaction Cisco ASA dataset, expanding decoy coverage for network security appliances and improving detection fidelity for attackers targeting perimeter infrastructure.

For full release notes: https://help.zscaler.us/deception/release-upgrade-summary-2026

Authentication Service (Zidentity)

The Zscaler Authentication Service (Zidentity) provides centralized identity and access management for the Zscaler platform. It supports authentication policies, MFA enforcement, and user lifecycle controls that help agencies meet identity-centric zero trust requirements.

This month's update introduces customizable password policies for stronger credential hygiene.

Highlights

  • Customize Password Policy: Admins can now configure account deactivation after a set number of unsuccessful login attempts and reject a configurable number of previously used passwords. Both settings are customizable from 3 to 10, supporting compliance with organizational and federal password policy standards.

For full release notes: https://help.zscaler.us/zidentity/release-upgrade-summary-2026

Conclusion

Want the full details? Use the links above to review the complete release summaries, and check back next month for the next GovCloud update roundup.

Zscaler continues to invest in a robust GovCloud roadmap and remains committed to supporting the unique security, compliance, and operational requirements of the federal market. We'll keep delivering enhancements that help agencies and federal partners strengthen resilience, simplify operations, and advance mission success.

form submtited
Merci d'avoir lu l'article

Cet article a-t-il été utile ?

Clause de non-responsabilité : Cet article de blog a été créé par Zscaler à des fins d’information uniquement et est fourni « en l’état » sans aucune garantie d’exactitude, d’exhaustivité ou de fiabilité. Zscaler n’assume aucune responsabilité pour toute erreur ou omission ou pour toute action prise sur la base des informations fournies. Tous les sites Web ou ressources de tiers liés à cet article de blog sont fournis pour des raisons de commodité uniquement, et Zscaler n’est pas responsable de leur contenu ni de leurs pratiques. Tout le contenu peut être modifié sans préavis. En accédant à ce blog, vous acceptez ces conditions et reconnaissez qu’il est de votre responsabilité de vérifier et d’utiliser les informations en fonction de vos besoins.

Recevez les dernières mises à jour du blog de Zscaler dans votre boîte de réception

En envoyant le formulaire, vous acceptez notre politique de confidentialité.