Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Netskope

First CVE: Sep 26, 2019Active for: 7 yearsTotal CVEs: 10
40.9
VTI Score
High

Netskope develops cloud access and security products that mediate enterprise traffic and data flows, positioning the vendor in a critical visibility and enforcement layer for organizations adopting cloud services and remote work. Its vulnerability footprint concentrates in a narrowly scoped product line and recurs through weakness classes including improper privilege management, buffer overflows, authentication bypasses, path traversal, and CSV injection—a pattern reflecting both the parsing demands of network inspection and the access-control complexity inherent to a security enforcement platform. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
1.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
7.9
Avg CVSS Score
Higher Avg CVSS Score than 77% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Netskope over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 26, 2019
6 years ago
Most Recent CVE
Aug 26, 2024
697 days ago

Self-Reporting Analysis

Of all the CVEs published by Netskope as a CNA, 29.4% affect products that Netskope develops as a vendor.

29.4%
70.6%
Self-reported: 5 (29.4%)
Third-party: 12 (70.6%)

Of all the CVEs published that affect products developed by Netskope, 50.0% are self-published by Netskope as a CNA.

50.0%
50.0%
Self-published: 5 (50.0%)
Other CNAs: 5 (50.0%)

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-24576HIGH
Netskope Client through 77 allows low-privileged users to elevate their privileges to NT AUTHORITY\SYSTEM.
Aug 12, 20218.827NONO
CVE-2021-44862HIGH
Netskope client is impacted by a vulnerability where an authenticated, local attacker can view sensitive information stored in NSClient logs which should be restricted. The vulnera
Nov 3, 20227.825NONO
CVE-2021-41388HIGH
Netskope client prior to 89.x on macOS is impacted by a local privilege escalation vulnerability. The XPC implementation of nsAuxiliarySvc process does not perform validation on ne
Jan 4, 20227.825NONO
CVE-2024-7401HIGH
Netskope was notified about a security gap in Netskope Client enrollment process where NSClient is using a static token “Orgkey” as authentication parameter. Since this is a static
Aug 26, 20247.524NONO
CVE-2023-4996HIGH
Netskope was made aware of a security vulnerability in its NSClient product for version 100 & prior where a malicious non-admin user can disable the Netskope client by using a spec
Nov 6, 20238.824NONO
CVE-2019-12091HIGH
The Netskope client service, v57 before 57.2.0.219 and v60 before 60.2.0.214, running with NT\SYSTEM privilege, accepts network connections from localhost. The connection handling
Sep 26, 20197.824NONO
CVE-2019-10882HIGH
The Netskope client service, v57 before 57.2.0.219 and v60 before 60.2.0.214, running with NT\SYSTEM privilege, accepts network connections from localhost. The connection handling
Sep 26, 20197.824NONO
CVE-2023-2270HIGH
The Netskope client service running with NT\SYSTEM privileges accepts network connections from localhost to start various services and execute commands. The connection handling fun
Jun 15, 20237.821NONO
CVE-2020-28845HIGH
A CSV injection vulnerability in the Admin portal for Netskope 75.0 allows an unauthenticated user to inject malicious payload in admin's portal thus leads to compromise admin's sy
Nov 20, 20207.820NONO
CVE-2022-4149HIGH
The Netskope client service (prior to R96) on Windows runs as NT AUTHORITY\SYSTEM which writes log files to a writable directory (C:\Users\Public\netSkope) for a standard user. The
Jun 15, 20237.018NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
100%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
High
Attack Vector
Local7 (70.0%)
Network3 (30.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (90.0%)
High1 (10.0%)
Unknown0 (0.0%)
User Interaction
None9 (90.0%)
Unknown0 (0.0%)
Required1 (10.0%)
Privileges Required
Low8 (80.0%)
High0 (0.0%)
None2 (20.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Netskope.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Netskope — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Netskope's Products

View all 3 CNAs →

Top CWEs