Network security

Netskope advisories: every record the registers tie to its products

In one line

17 advisories are attributed to Netskope products in this record, covering November 2022 to June 2026, and none of them appears in the CISA catalogue of known exploited vulnerabilities. A further 5 register entries mention Netskope without naming one of its products as affected, and are excluded rather than counted. Each entry below links to the register that published it.

Attributed

17

tied to a named product

Known exploited

0

in the CISA catalogue

Rated critical

0

by the register

Last checked

Jul 18, 2026

sources re-queried

Why this list is shorter than a CVE mirror

The registers are searched by keyword, so a search for a company name returns advisories that merely mention it. A mirror publishes those. This page does not: an entry appears only when the register itself ties it to a product of Netskope, through a reference on the vendor's own domain, the vendor named as the assigning authority, or the affected product list naming it.

5 entries did not clear that bar and are not shown. That is the difference, and it is deliberate: a page that lists another company's vulnerability under this heading is wrong in the way that matters most.

17 of the 17 records carry a CVSS base score from the register. Where none is published, none is shown, and no score is estimated.

The full list, most recently exploited and most recent first

Records held by several registers are folded into one entry with a link to each, so the same vulnerability is not counted twice. Entries listed in the CISA catalogue of known exploited vulnerabilities are shown first, because that is the one flag on this page that changes what a reader should do next.

  • CVE-2025-15642mediumCVSS 6.8Jun 17, 2026

    Netskope is notified about a potential gap in its Netskoped Client for Windows systems where a malicious insider with admin privileges can lead to bypassing the NSClient Tamper Protections…

  • CVE-2025-15641mediumCVSS 6.8Jun 17, 2026

    Netskope was notified about a potential gap in its Netskope Client for Windows systems where a malicious insider with administrative privileges can potentially tamper with the customer…

  • CVE-2026-2810mediumCVSS 6.8Apr 29, 2026

    Netskope was notified about a potential gap in the Endpoint DLP Module for Netskope Client on Windows systems.

  • CVE-2026-2809mediumCVSS 6.7Mar 17, 2026

    Netskope was notified about a potential gap in its Endpoint DLP Module for Netskope Client on Windows systems.

  • CVE-2025-15584mediumCVSS 6.8Mar 17, 2026

    Netskope was notified about a potential gap in its Endpoint DLP Module for Netskope Client on Windows systems.

  • CVE-2025-11156mediumCVSS 5.9Nov 28, 2025

    Netskope was notified about a potential gap in its agent (NS Client) on Windows systems.

  • CVE-2025-5942mediumCVSS 5.7Aug 14, 2025

    Netskope was notified about a potential gap in its agent (NS Client) on Windows systems.

  • CVE-2025-5941lowCVSS 2.0Aug 14, 2025

    Netskope is notified about a potential gap in its agent (NS Client) in which a malicious actor could trigger a memory leak by sending a crafted DNS packet to a machine.

  • CVE-2025-0309mediumCVSS 6.0Aug 14, 2025

    An insufficient validation on the server connection endpoint in Netskope Client allows local users to elevate privileges on the system.

  • CVE-2024-7402highCVSS 7.0Aug 14, 2025

    Netskope has identified a potential gap in its agent (Netskope Client) in which a malicious insider can potentially tamper the Netskope Client configuration by performing MITM…

  • CVE-2024-13177mediumCVSS 5.2Apr 15, 2025

    Netskope Client on Mac OS is impacted by a vulnerability in which the postinstall script does not properly validate the path of the file “nsinstallation”.

  • CVE-2024-11616mediumCVSS 5.6Dec 19, 2024

    Netskope was made aware of a security vulnerability in Netskope Endpoint DLP’s Content Control Driver where a double-fetch issue leads to heap overflow.

  • CVE-2024-7401highCVSS 8.5Aug 26, 2024

    Netskope was notified about a security gap in Netskope Client enrollment process where NSClient is using a static token “Orgkey” as authentication parameter.

  • CVE-2023-4996mediumCVSS 6.6Nov 06, 2023

    Netskope was made aware of a security vulnerability in its NSClient product for version 100 & prior where a malicious non-admin user can disable the Netskope client by using a…

  • CVE-2022-4149highCVSS 7.0Jun 15, 2023

    The Netskope client service (prior to R96) on Windows runs as NT AUTHORITY\SYSTEM which writes log files to a writable directory (C:\Users\Public\netSkope) for a standard user.

  • CVE-2023-2270highCVSS 7.0Jun 15, 2023

    The Netskope client service running with NT\SYSTEM privileges accepts network connections from localhost to start various services and execute commands.

  • CVE-2021-44862highCVSS 8.4Nov 03, 2022

    Netskope client is impacted by a vulnerability where an authenticated, local attacker can view sensitive information stored in NSClient logs which should be restricted.

Which registers contributed

RegisterOperated byEntriesLatest
European Vulnerability DatabaseENISA, European Union22Jun 17, 2026
National Vulnerability DatabaseNIST, United States Department of Commerce10Jun 17, 2026

The entry counts here are the raw register totals for Netskope, before attribution. They are larger than the list above for exactly that reason.

Questions this page answers

How many vulnerabilities does Netskope have?

17 advisories in this record are tied by a register to a product of Netskope. That is not the same as the number of vulnerabilities the products contain, and no public source knows that number. It is the count of what has been found, disclosed and published, which depends on how much the products are examined and how openly the vendor discloses.

Are any Netskope vulnerabilities being actively exploited?

None of the 17 records here appears in the CISA catalogue of known exploited vulnerabilities. That catalogue is not exhaustive: it lists what CISA has confirmed as exploited, so absence from it is not proof that nothing has been exploited.

Why does this page show fewer CVEs for Netskope than other sites?

Because a keyword search for a company name returns advisories about other companies' products that mention it in passing, and this page excludes those. 5 register entries name Netskope without naming one of its products as affected. A mirror that lists them produces a longer page and a wrong number.

Where do the Netskope advisories on this page come from?

From European Vulnerability Database (ENISA, European Union); National Vulnerability Database (NIST, United States Department of Commerce). Every entry links back to the register that published it, and carries the date that register states. Where the same vulnerability is held by several registers it is shown once with a link to each, rather than counted twice.

Does a long advisory list mean Netskope is insecure?

No. A register records what researchers found and what the vendor disclosed, so a widely deployed product with a working disclosure process accumulates more entries than one nobody examines. A short list can equally mean a small install base or a vendor that publishes little. This page reports the record and does not rate the vendor, because whether this is acceptable depends on your risk appetite, your compliance scope and the alternatives you are weighing.

A list of advisories is not a risk assessment

What matters is which of these touch the components you actually run, in the configuration you actually run them in, and whether that is acceptable next to the alternatives on your shortlist. DecisionOS reads the same pool against the criteria of a real decision and produces a memo that holds up in front of a board and an auditor.

The full Netskope record, including sources and open questions

Netskope vulnerabilities: all 17 advisories on record, with sources | DecisionOS by nexalign