Out-of-Bounds Read Vulnerability in Netskope Endpoint DLP Module for Windows
CVE-2026-2810

6.8MEDIUM

Key Information:

Vendor

Netskope

Status
Vendor
CVE Published:
29 April 2026

What is CVE-2026-2810?

A vulnerability has been identified in the Endpoint DLP Module for Netskope Client on Windows systems. This flaw allows unprivileged users to potentially exploit an out-of-bounds read situation within the device driver. If successfully triggered, this could lead to a Blue Screen of Death (BSOD), resulting in a complete denial-of-service for the affected machine. It is important to note that in order for this exploit to succeed, the Endpoint DLP module must be activated in the client’s configuration.

Affected Version(s)

Client Windows 0 < 129.1.8,132.0.23,135.1.0,136.1

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tom Brice
.