Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Cato Networks — Vulnerabilities & Security Advisories 11

Browse all 11 CVE security advisories affecting Cato Networks. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Cato Networks provides a cloud-delivered SASE platform integrating network security functions. Historically, vulnerabilities have included remote code execution, cross-site scripting, and privilege escalation issues. The company has recorded 8 CVEs, with some flaws allowing unauthorized access or system compromise. While no major public security incidents have been widely reported, the presence of multiple CVEs indicates potential attack surfaces. The platform's centralized architecture and cloud-native design offer security advantages but also create dependencies that could be targeted. Organizations implementing Cato should prioritize timely patching and regular security assessments to mitigate identified risks.

Top products by Cato Networks: SDP Client Cato Client Socket
CVE ID Title CVSS Severity Published
CVE-2026-10726 Cato Windows SDP Client arbitrary file disclosure due to improper TLS certificate validation — SDP Client CWE-295 6.8 Medium 2026-09-30
CVE-2026-10739 Cato Networks SDP Client for Windows is vulnerable to Local Privilege Escalation — SDP Client CWE-23 8.5 High 2026-09-30
CVE-2026-12374 Improper XPC caller certificate validation and TOCTOU race condition in macOS PrivilegedHelperTool — SDP Client CWE-295 - - 2026-07-01
CVE-2025-14213 Cato's Socket WebUI is vulnerable to OS Command Injection — Socket CWE-78 8.8AI High AI 2026-03-31
CVE-2025-7012 Cato Networks Linux Client Local Privilege Escalation via Symlink — Cato Client CWE-59 7.8AI High AI 2025-07-13
CVE-2025-3886 CatoNetworks CatoClient up to 5.8 PrivilegedHelperTool Race Condition — SDP Client CWE-362 7.5 - 2025-04-27
CVE-2024-6978 Cato Networks Windows SDP Client Local root certificates can be installed by low-privileged users — SDP Client CWE-20 5.6 Medium 2024-07-31
CVE-2024-6977 Cato Networks Windows SDP Client Sensitive data in trace logs can lead to account takeover — SDP Client CWE-532 6.5 Medium 2024-07-31
CVE-2024-6975 Cato Networks Windows SDP Client Local Privilege Escalation via openssl configuration file — SDP Client CWE-426 8.8 High 2024-07-31
CVE-2024-6974 Cato Networks Windows SDP Client Local Privilege Escalation via self-upgrade — SDP Client CWE-426 8.8 High 2024-07-31
CVE-2024-6973 Remote Code Execution in Cato Windows SDP client via crafted URLs — SDP Client CWE-20 7.5 High 2024-07-31

This page lists every published CVE security advisory associated with Cato Networks. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.