CVE-2026-16174

HIGH CVSS 4.0: 8.7 EPSS 0.13%
Updated Sep 11, 2026
Netskope
Parameter Value
CVSS 8.7 (HIGH)
Type CWE-190 (Integer Overflow)
Vendor Netskope
Public PoC No

Netskope was notified about a potential gap in Netskope Endpoint DLP (EPDLP) running on Windows systems. Successful exploitation of the gap could potentially allow a privileged user to send a crafted message to the EPDLP process port to trigger an integer overflow, leading to memory corruption. Successful exploitation would require the EPDLP module to be enabled in the client configuration, and that Memory Integrity is disabled.

A successful exploit could potentially result in a denial-of-service, arbitrary code execution, or privilege escalation on the local machine.

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
Low
Easy to exploit
Attack Requirements
Present
Additional conditions required
Privileges Required
High
Admin privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v4.0

Weakness Type (CWE)

Vulnerable Products

netskope:endpoint dlp