Public updates from vendor feeds, with related items from the same catalog.
Here is the list of fixed issues in this release.
| Issue Number | Category | Description |
|---|---|---|
1086114 | AI Command Center (AICC) | Fixed an issue where the alert count on AI Command Center > Overview > Alerts did not match alerts shown on SkopeIT > Alerts. Clicking View all threat Alerts now redirects with the correct filters and shows matching results. |
1073183 | CASB Inline Protection | Fixed an issue where spell check in Outlook was not functioning when accessed via Reverse Proxy. The fix adds CSP rewrite rules for the newer Microsoft AugLoop WebSocket domains (augloop.svc.cloud.microsoft and augloop-gcc.office.com), allowing the real-time spell/grammar check service to connect successfully. |
1026540 | Resolved an issue where PowerPoint Online presentations accessed through reverse proxy would hang on “Please wait… We’re still loading the presentation,” with Animations, Transitions, and Design ribbon features unavailable. The fix removes that enforcement directive from the CSP header on PowerPoint ppt.aspx responses, restoring full functionality. No impact on Word, Excel, SharePoint, or other Office apps. | |
1026352 | Based on the ticket details, this is a bug fix for Microsoft Teams access issues in the GCCH environment via reverse proxy. The CSP regex pattern was crossing directive boundaries, causing browser script blocks. | |
1016647 | Resolved an issue where multi-file and folder zip downloads from Microsoft OneDrive and SharePoint were failing with authentication errors (401) when accessed through the Reverse Proxy. The issue was caused by a Microsoft-side traffic change in how OneDrive Personal handles bulk download authentication tokens. The token restoration logic has been updated to correctly handle the new token format, restoring successful bulk downloads. | |
1013745 | Resolved an issue where Microsoft Power Apps workflows linked from SharePoint Online failed to load correctly when accessed via Reverse Proxy in GCC High (GCCH) environments. Users experienced authentication redirects and 502 errors when Power Apps attempted to access SharePoint-hosted files. The fix adds support for powerapps.us and azure-apihub.us domains in Reverse Proxy rewrite rules and resolves hostname decoding for Power Platform GCCH gateways. | |
1085008 | Cloud Firewall (CFW) | Enhanced DNS security now more effectively detects covert DNS tunneling used for C2 communication, data exfiltration, and inbound payload delivery, strengthening protection against sophisticated threats while maintaining high detection accuracy. |
1109467 | Resolved a bug where legitimate DNS requests would gradually start getting blocked in error after a client’s DNS tunneling activity was flagged, due to improper handling of internal UDP flows. | |
993907 | Email DLP | Fixed a reporting issue in environments utilizing Async DLP where real-time SMTP email logs, transaction alerts, and application events incorrectly displayed the application category as n/a in the SkopeIT console. The classification engine has been corrected to properly pass the category payload data to the event processor, ensuring that all matching SMTP email alerts are accurately indexed and labeled as Webmail within the Netskope UI. |
1097851 | Netskope Client Steering | Fixed an issue where the Netskope Client on Windows crashed during On-Premises Detection. The app crashed because two detection processes tried to use the same shared data at the same time without proper coordination. This affected Clients on versions 135.0.0 and 138.0.0, causing temporary loss of traffic visibility and security enforcement until the Client restarted. |
1068088 | Fixed an issue on Windows where the Netskope Client reported 0 bytes for inbound and outbound traffic when monitoring AI application connections. This occurred because Windows released the connection data before the Client could read it when the application abruptly closed the connection. The Client now caches byte counts as a fallback. | |
1064299 | Fixed an issue on macOS where the Netskope Client stayed disabled after upgrading to 138.0.0. The Client failed to read the user certificate because it attempted to access session data before a valid user session was established. A validation check now ensures a valid session exists before reading the certificate. If a valid user session does not exist, then it does not attempt to create a tunnel for that session. | |
1059302 | Fixed an issue where the Netskope Client lost its user certificate during enrollment when certain certificate files were missing on disk. This caused authentication failures and required a reinstall to recover. The Client now preserves the existing certificate to maintain connectivity. | |
1053272 | Fixed an issue on Windows where the Netskope Client could enter fail-close after a reboot when a system account signed in before the actual user. This could block traffic until the enrolled user signed in. | |
1036346 | Improved security for the captive portal pop-up message on Windows. The captive portal dialog now includes protections to prevent misuse by malicious Wi-Fi networks, such as blocking unauthorized downloads, preventing access to developer tools, and automatically closing the window when the network disconnects. Contact Netskope Support to enable the fix for your tenant. | |
1064301 | Fixed an issue where the Share dialog in Microsoft Office apps had an indefinite loading period for SharePoint users. The Netskope Client now makes the Office Share dialog send its SharePoint traffic through the Netskope tunnel, so SharePoint recognizes it as trusted traffic and the dialog opens as expected. | |
1053204 | Fixed an issue where devices deployed from the same base image could share identical device IDs, causing incorrect device-to-user mapping in the DEM dashboard. As part of this, you can enable a new configuration option that lets the Netskope Client automatically detects and regenerates duplicate device IDs, ensuring each device is uniquely identified. This option is disabled by default; contact Netskope support to enable it for affected environments. | |
1070921 | Fixed an issue where Netskope Client (stAgentSvc.exe) crashed intermittently on Windows endpoints during network policy updates, causing complete loss of internet connectivity. The crash was triggered by a race condition in the custom DNS port configuration when a steering policy reload coincided with active network traffic. Users experienced an “Internet Security has an error” message in the system tray and required a manual service restart or endpoint reboot to restore connectivity. This issue has been resolved by adding proper thread synchronization to the DNS steering configuration, preventing heap corruption during concurrent policy updates. | |
973650 | Fixed an issue where custom application routing through BWAN tunnels stopped working on Linux platform after a tunnel reconnection. Previously, when the BWAN tunnel reconnected, DNS lookups for custom apps configured with domain names could fail, causing traffic to not route correctly. This has been resolved, and custom app routing now recovers seamlessly after tunnel reconnections. | |
1022611 | Fixed an issue where Microsoft Self-Service Password Reset (SSPR) failed on Windows devices with Netskope Client installed. During a reboot, the Netskope Client incorrectly treated a built-in Windows system account as an active user session, triggering fail-close mode and blocking network traffic before login. This prevented SSPR from reaching Microsoft’s servers. The Netskope Client now correctly ignores built-in system accounts during reboot, allowing SSPR to work as expected. | |
1107289 | Fixed an issue where the Netskope Client upgrade on Windows could fail or hang when Digital Experience Management (DEM) was enabled. Previously, when DEM was enabled, the Netskope Client service took more time to stop during an upgrade, causing the upgrade to fail. This occurred because DEM tasks did not stop promptly when the Client service was shutting down. With this fix, the Client service now shuts down properly and within the expected time, ensuring smooth client upgrades. Note: This is fix is getting back ported to version 138.1.10 and 135.1.22. | |
936464 | Netskope Public Cloud Security | Fixed an issue where uploading more than 50 AWS instances in a single request created the instances successfully on the IaaS Instances page, but the instances failed to sync to the App Instances page under Profile. This happened due to an internal API timeout. A limit of 30 instances per request is now enforced. Attempting to exceed the limit returns an error instead of failing silently. |
1073958 | Netskope Secure Web Gateway (NG SWG) | Policy Changes Now Apply Reliably With Empty Organizational Unit Names Applying policy changes could previously trigger an error if a policy referenced an organizational unit with an empty name. This is now fixed, so policy updates apply cleanly regardless of that configuration. |
1041556 | Application Events Now Show the Forward-To Profile Name Application events for traffic processed by an RTP policy’s forward-to profile action now display the profile’s name, instead of its identifier. | |
1027772 | Accurate Byte Counts for HTTP/2 Transactions in SkopeIT SkopeIT transaction events now report accurate client and server byte counts for connections running over HTTP/2 — including cases that previously showed sc-bytes as 0. Upload, download, and total processed byte metrics now reflect true on-the-wire network utilization for HTTP/2 traffic. | |
1022410 | Clear Validation for Destination Profile Evaluation API Requests The destination profile evaluation API ( /api/v2/profiles/destinations/getevaluation) now correctly rejects requests with an IPv6 address used as the FQDN in the URL (for example, https://[2001:db8::1]).Since IPv6 URL FQDNs aren’t currently supported for remote IP extraction, these requests now return an HTTP 400 (Bad Request) instead of an HTTP 200 — so you’ll know right away that the request needs a different format, rather than getting a success response that wasn’t actually evaluated. | |
1089506 | AD/SCIM Group Names with Special Characters Now Accepted in Real-Time Protection Policies Inline policies under Real-Time Protection now accept AD/SCIM group names containing less-than (<) or greater-than (>) characters, so you can save or edit policies without hitting a false “invalid value” error. Previously, a group name like One Platform > AI Platform was rejected even though it existed in the directory. This is now fixed. | |
975038 | The x-ssl-policy-name Field Now Always Populated in Transaction Events Transaction events now always populate the x-ssl-policy-name field, so you can reliably verify which SSL decryption rule processed any given connection. For connections handled by default SSL settings, this field now shows DefaultAction instead of appearing empty. | |
1083478 | Platform Services | Fixed an issue where ADImporter timed out during LDAP user synchronization when querying large dynamic groups. The LDAP query timeout is now configurable, and performance has been improved by removing unnecessary attributes from dynamic group queries and eliminating duplicate attribute entries. |
1069195 | URLC | Fixed an issue in the URL lookup service where safe, well-known websites explicitly indexed in Netskope’s static database (such as google.com) were incorrectly flagged with a Dynamically Classified: true status in system logs. This occurred because a background DNS check evaluating the site’s underlying IP address mistakenly overrode the primary domain classification state. The logging merge logic has been corrected to prevent secondary IP resolution tracking from altering the classification flags of established static database results. |
More recent public updates for Netskope.