Skygroup's vulnerability profile centers on a narrow portfolio of endpoint detection and response (EDR) and client management products, including SkySea Client View and EDR Plus Pack variants, which occupy a prominent position in enterprise security infrastructure despite modest product breadth. Vulnerabilities affecting the vendor cluster around access control, authentication, and privilege management weaknesses, alongside path-traversal and exception-handling flaws that are characteristic of agent-based endpoint software; these recur with a meaningful tendency toward confirmed in-the-wild exploitation. Defenders should prioritize patches for these products given their deep integration into endpoint security posture; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Skygroup over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-7836CRITICAL SKYSEA Client View Ver.11.221.03 and earlier allows remote code execution via a flaw in processing authentication on the TCP connection with the management console program. | Jun 9, 2017 | 9.8 | 78 | YES | NO |
CVE-2026-39454HIGH SKYSEA Client View and SKYMEC IT Manager provided by Sky Co.,LTD. configure the installation folder with improper file access permission settings. A non-administrative user may man | Apr 20, 2026 | 7.8 | 28 | NO | NO |
CVE-2024-41139HIGH Incorrect privilege assignment vulnerability exists in SKYSEA Client View Ver.6.010.06 to Ver.19.210.04e. If a user who can log in to the PC where the product's Windows client is i | Jul 29, 2024 | 7.8 | 24 | NO | NO |
CVE-2024-21805HIGH Improper access control vulnerability exists in the specific folder of SKYSEA Client View versions from Ver.16.100 prior to Ver.19.2. If this vulnerability is exploited, an arbitra | Mar 12, 2024 | 7.8 | 24 | NO | NO |
CVE-2021-20616HIGH Untrusted search path vulnerability in the installer of SKYSEA Client View Ver.1.020.05b to Ver.16.001.01g allows an attacker to gain privileges via a Trojan horse DLL in an unspec | Jan 13, 2021 | 7.8 | 24 | NO | NO |
CVE-2024-41726HIGH Path traversal vulnerability exists in SKYSEA Client View Ver.3.013.00 to Ver.19.210.04e. If this vulnerability is exploited, an arbitrary executable file may be executed by a user | Jul 29, 2024 | 7.5 | 23 | NO | NO |
CVE-2024-41143HIGH Origin validation error vulnerability exists in SKYSEA Client View Ver.3.013.00 to Ver.19.210.04e. If this vulnerability is exploited, an arbitrary process may be executed with SYS | Jul 29, 2024 | 7.8 | 23 | NO | NO |
CVE-2024-24964MEDIUM Improper access control vulnerability exists in the resident process of SKYSEA Client View versions from Ver.11.220 prior to Ver.19.2. If this vulnerability is exploited, an arbitr | Mar 12, 2024 | 6.3 | 21 | NO | NO |
CVE-2020-5617HIGH Privilege escalation vulnerability in SKYSEA Client View Ver.12.200.12n to 15.210.05f allows an attacker to obtain unauthorized privileges and modify/obtain sensitive information o | Aug 4, 2020 | 7.8 | 20 | NO | NO |
"FFRI yarai", "FFRI yarai Home and Business Edition" and their OEM products handle exceptional conditions improperly, which may lead to denial-of-service (DoS) condition.
Affecte | Aug 9, 2023 | 3.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Skygroup.
Media articles that mention a CVE ID that affects a product developed by Skygroup — matched by CVE ID, not by vendor name.