VYPR
Medium severityNVD Advisory· Published Apr 29, 2026· Updated Apr 30, 2026

CVE-2026-2810

CVE-2026-2810

Description

Netskope was notified about a potential gap in the Endpoint DLP Module for Netskope Client on Windows systems. The successful exploitation of the gap can potentially allow an unprivileged user to trigger an out-of-bounds read within a driver, leading to a Blue-Screen-of-Death (BSOD). Successful exploitation would require the Endpoint DLP module to be enabled in the client configuration. A successful exploit can potentially result in a denial-of-service for the local machine.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Unprivileged user can trigger out-of-bounds read in Netskope Endpoint DLP driver on Windows, causing BSOD denial-of-service.

CVE-2026-2810 describes a vulnerability in the Endpoint DLP Module of the Netskope Client on Windows systems. The issue allows an unprivileged user to trigger an out-of-bounds read within a kernel driver, leading to a Blue Screen of Death (BSOD) [1]. The root cause is a flaw in how the driver handles certain input from user space.

Exploitation requires the Endpoint DLP module to be enabled in the client configuration. An attacker must have local unprivileged access to the system to trigger the out-of-bounds read, which then causes the system to crash [1]. No network access or additional privileges are needed.

Successful exploitation results in a denial-of-service (DoS) condition, crashing the Windows machine and requiring a reboot. The impact is limited to local system availability; there is no evidence of data breach or privilege escalation [1].

Netskope has released patches: R136.1 and above, with backports to R129.1.8, R132.0.23, and R135.1.0 [1]. No workarounds are available. The vulnerability was reported by Tom Brice, and Netskope is not aware of any active exploitation.

References
  1. NSKPSA-2026-002

AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.