Netskope develops cloud access and security products that mediate enterprise traffic and data flows, positioning the vendor in a critical visibility and enforcement layer for organizations adopting cloud services and remote work. Its vulnerability footprint concentrates in a narrowly scoped product line and recurs through weakness classes including improper privilege management, buffer overflows, authentication bypasses, path traversal, and CSV injection—a pattern reflecting both the parsing demands of network inspection and the access-control complexity inherent to a security enforcement platform. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Netskope over time
Of all the CVEs published by Netskope as a CNA, 29.4% affect products that Netskope develops as a vendor.
Of all the CVEs published that affect products developed by Netskope, 50.0% are self-published by Netskope as a CNA.
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-24576HIGH Netskope Client through 77 allows low-privileged users to elevate their privileges to NT AUTHORITY\SYSTEM. | Aug 12, 2021 | 8.8 | 27 | NO | NO |
CVE-2021-44862HIGH Netskope client is impacted by a vulnerability where an authenticated, local attacker can view sensitive information stored in NSClient logs which should be restricted. The vulnera | Nov 3, 2022 | 7.8 | 25 | NO | NO |
CVE-2021-41388HIGH Netskope client prior to 89.x on macOS is impacted by a local privilege escalation vulnerability. The XPC implementation of nsAuxiliarySvc process does not perform validation on ne | Jan 4, 2022 | 7.8 | 25 | NO | NO |
CVE-2024-7401HIGH Netskope was notified about a security gap in Netskope Client enrollment process where NSClient is using a static token “Orgkey” as authentication parameter. Since this is a static | Aug 26, 2024 | 7.5 | 24 | NO | NO |
CVE-2023-4996HIGH Netskope was made aware of a security vulnerability in its NSClient product for version 100 & prior where a malicious non-admin user can disable the Netskope client by using a spec | Nov 6, 2023 | 8.8 | 24 | NO | NO |
CVE-2019-12091HIGH The Netskope client service, v57 before 57.2.0.219 and v60 before 60.2.0.214, running with NT\SYSTEM privilege, accepts network connections from localhost. The connection handling | Sep 26, 2019 | 7.8 | 24 | NO | NO |
CVE-2019-10882HIGH The Netskope client service, v57 before 57.2.0.219 and v60 before 60.2.0.214, running with NT\SYSTEM privilege, accepts network connections from localhost. The connection handling | Sep 26, 2019 | 7.8 | 24 | NO | NO |
CVE-2023-2270HIGH The Netskope client service running with NT\SYSTEM privileges accepts network connections from localhost to start various services and execute commands. The connection handling fun | Jun 15, 2023 | 7.8 | 21 | NO | NO |
CVE-2020-28845HIGH A CSV injection vulnerability in the Admin portal for Netskope 75.0 allows an unauthenticated user to inject malicious payload in admin's portal thus leads to compromise admin's sy | Nov 20, 2020 | 7.8 | 20 | NO | NO |
CVE-2022-4149HIGH The Netskope client service (prior to R96) on Windows runs as NT AUTHORITY\SYSTEM which writes log files to a writable directory (C:\Users\Public\netSkope) for a standard user. The | Jun 15, 2023 | 7.0 | 18 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Netskope.
Media articles that mention a CVE ID that affects a product developed by Netskope — matched by CVE ID, not by vendor name.