Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. Netskope/
  3. Netskope One SSE

Netskope One SSE

SSEAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 22 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~47 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

Security service edge platform.

by Netskope · netskope.com

Known CVEs (22)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2025-15642 ↗2026

    Netskope is notified about a potential gap in its Netskoped Client for Windows systems where a malicious insider with admin privileges can lead to bypassing the NSClient Tamper Protections due to weak…

  • CVE-2025-15641 ↗2026

    Netskope was notified about a potential gap in its Netskope Client for Windows systems where a malicious insider with administrative privileges can potentially tamper with the customer IOCTL by sendin…

  • CVE-2026-2810 ↗2026

    Netskope was notified about a potential gap in the Endpoint DLP Module for Netskope Client on Windows systems. The successful exploitation of the gap can potentially allow an unprivileged user to trig…

  • CVE-2026-2809 ↗2026

    Netskope was notified about a potential gap in its Endpoint DLP Module for Netskope Client on Windows systems. The successful exploitation of the gap can potentially allow a privileged user to trigger…

  • CVE-2025-15584 ↗2026

    Netskope was notified about a potential gap in its Endpoint DLP Module for Netskope Client on Windows systems. The successful exploitation of the gap can potentially allow an unprivileged user to trig…

  • CVE-2025-11156 ↗2025

    Netskope was notified about a potential gap in its agent (NS Client) on Windows systems. If this gap is successfully exploited, a local, authenticated user with Administrator privileges can improperl…

  • CVE-2025-5942 ↗2025

    Netskope was notified about a potential gap in its agent (NS Client) on Windows systems. If this gap is successfully exploited, an unprivileged user can trigger a heap overflow in the epdlpdrv.sys dr…

  • CVE-2025-5941 ↗2025

    Netskope is notified about a potential gap in its agent (NS Client) in which a malicious actor could trigger a memory leak by sending a crafted DNS packet to a machine. A successful exploitation may r…

  • CVE-2025-0309 ↗2025

    An insufficient validation on the server connection endpoint in Netskope Client allows local users to elevate privileges on the system. The insufficient validation allows Netskope Client to connect to…

  • CVE-2024-7402 ↗2025

    Netskope has identified a potential gap in its agent (Netskope Client) in which a malicious insider can potentially tamper the Netskope Client configuration by performing MITM (Man-in-the-Middle) acti…

  • CVE-2024-13177 ↗2025

    Netskope Client on Mac OS is impacted by a vulnerability in which the postinstall script does not properly validate the path of the file “nsinstallation”. A standard user could potentially create a sy…

  • CVE-2024-11616 ↗2024

    Netskope was made aware of a security vulnerability in Netskope Endpoint DLP’s Content Control Driver where a double-fetch issue leads to heap overflow. The vulnerability arises from the fact that the…

  • CVE-2024-7401 ↗HIGH 7.52024

    Netskope was notified about a security gap in Netskope Client enrollment process where NSClient is using a static token “Orgkey” as authentication parameter. Since this is a static token, if leaked, c…

  • CVE-2023-4996 ↗MEDIUM 6.62023

    Netskope was made aware of a security vulnerability in its NSClient product for version 100 & prior where a malicious non-admin user can disable the Netskope client by using a specially-crafted packag…

  • CVE-2022-4149 ↗HIGH 7.02023

    The Netskope client service (prior to R96) on Windows runs as NT AUTHORITY\SYSTEM which writes log files to a writable directory (C:\Users\Public\netSkope) for a standard user. The files are created a…

  • CVE-2023-2270 ↗HIGH 7.02023

    The Netskope client service running with NT\SYSTEM privileges accepts network connections from localhost to start various services and execute commands. The connection handling function of Netskope cl…

  • CVE-2021-44862 ↗HIGH 8.42022

    Netskope client is impacted by a vulnerability where an authenticated, local attacker can view sensitive information stored in NSClient logs which should be restricted. The vulnerability exists becaus…

  • CVE-2021-41388 ↗HIGH 7.82022

    Netskope client prior to 89.x on macOS is impacted by a local privilege escalation vulnerability. The XPC implementation of nsAuxiliarySvc process does not perform validation on new connections before…

  • CVE-2020-24576 ↗HIGH 8.82021

    Netskope Client through 77 allows low-privileged users to elevate their privileges to NT AUTHORITY\SYSTEM.

  • CVE-2020-28845 ↗HIGH 7.82020

    A CSV injection vulnerability in the Admin portal for Netskope 75.0 allows an unauthenticated user to inject malicious payload in admin's portal thus leads to compromise admin's system.

  • …and 2 more

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other Secure Access Service Edge (SASE/SSE) products

see all →
  • 1Password Device Trust · 1Password
  • AWS Verified Access · Amazon Web Services, Inc.
  • Absolute Core · Absolute
  • Absolute Resilient, AI-powered SSE · Absolute
  • Agilicus · Agilicus
  • Akamai Enterprise Application Access · Akamai
  • Akamai Secure Internet Access Enterprise · Akamai
  • Alibaba Cloud Secure Access Service Edge · Alibaba Cloud