Integer Overflow Vulnerability in Netskope Endpoint DLP on Windows Systems
CVE-2026-16174

8.7HIGH

Key Information:

Vendor

Netskope

Vendor
CVE Published:
10 September 2026

What is CVE-2026-16174?

Netskope's Endpoint DLP (EPDLP) on Windows systems has been identified to have a vulnerability that allows a privileged user to execute a specially crafted message to the EPDLP process port. This could trigger an integer overflow, leading to critical memory corruption issues. Exploiting this vulnerability requires the EPDLP module to be activated in the client configuration with Memory Integrity disabled. Consequently, this could result in various attack vectors, such as denial-of-service conditions, arbitrary code execution, or privilege escalation on the affected local machine.

Affected Version(s)

Endpoint DLP Windows 0 < 141.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.