Security researchers revealed multiple critical vulnerabilities in Zero Trust Network Access (ZTNA) products at DEF CON 33 in August 2025, demonstrating serious authentication and access control weaknesses in major enterprise security solutions. The discovery comes at a crucial time when organizations are increasingly adopting ZTNA and SASE architectures for modern network security.
Researchers David Cash and Richard Warren from AmberWolf disclosed high-severity flaws affecting products from leading vendors including Zscaler, Netskope, and Check Point’s Perimeter 81. The vulnerabilities enable authentication bypass, cross-organization user impersonation, and privilege escalation – issues that directly challenge the core principles of zero trust security frameworks.
The specific vulnerabilities included an authentication bypass in Netskope Client’s Identity Provider enrollment (CVE-2024-7401), cross-organization user impersonation capabilities, privilege escalation via rogue server, a SAML authentication bypass in the Zscaler Platform (CVE-2025-54982), and hard-coded SFTP credentials in Check Point Perimeter 81. The findings are particularly concerning given the increasing focus on privileged access management in enterprise security.
The security flaws are especially significant as ZTNA solutions are increasingly replacing traditional VPN technology for enterprise remote access. “This type of multi-tenant data exposure represents a particularly serious breach of customer trust and data isolation,” noted Cash during the presentation.
The conference also featured demonstrations of vulnerabilities in smart bus systems and SSH protocol implementations, though these were unrelated to authentication systems. The revelations reflect growing scrutiny of enterprise authentication solutions at major security conferences, as shown by recent revelations about browser security and authentication vulnerabilities.
While authentication security was a major focus at DEF CON 33, no specific vulnerabilities were demonstrated regarding passkey technology, which uses public-key cryptography as a modern password replacement method. The emerging authentication standard has gained significant momentum with recent implementations by Microsoft and Meta.
“The vulnerabilities we discovered could allow attackers to completely bypass authentication mechanisms, impersonate users across different organizations, and gain unauthorized access to internal corporate resources,” explained Warren. The findings underscore the critical importance of robust security testing and continuous validation of zero trust implementations.
Sources: GBHackers, GBHackers, CyberPress