CVE-2026-2809 identifies an integer overflow vulnerability within the DLL Injector of the Netskope Client's Endpoint DLP Module on Windows systems. Exploitation requires a privileged local user and the Endpoint DLP module to be enabled, resulting in a medium severity rating with a CVSS score of 6.7. A successful exploit can lead to a Blue-Screen-of-Death (BSOD), causing a denial-of-service for the local machine. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Netskope | Endpoint DLP Module For Netskope Client | >= 0, < 132.0.20, 135CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.