Integer Overflow in Endpoint DLP Module for Netskope on Windows Systems
CVE-2026-2809

6.7MEDIUM

Key Information:

Vendor

Netskope

Vendor
CVE Published:
17 March 2026

What is CVE-2026-2809?

A critical vulnerability exists in the Endpoint DLP Module of the Netskope Client for Windows, where an integer overflow in the DLL Injector may be exploited by a privileged user. This exploitation can result in a system crash, commonly known as a Blue-Screen-of-Death (BSOD), leading to a local denial-of-service condition. For the attack to succeed, the Endpoint DLP module must be active in the client's settings, accentuating the importance of maintaining secure and updated configurations.

Affected Version(s)

Endpoint DLP Module for Netskope Client Windows 0 < 132.0.20, 135

References

CVSS V4

Score:
6.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tom Brice
.