CVE-2026-2810 Details
Description
Netskope was notified about a potential gap in the Endpoint DLP Module for Netskope Client on Windows systems. The successful exploitation of the gap can potentially allow an unprivileged user to trigger an out-of-bounds read within a driver, leading to a Blue-Screen-of-Death (BSOD). Successful exploitation would require the Endpoint DLP module to be enabled in the client configuration. A successful exploit can potentially result in a denial-of-service for the local machine.
A vulnerability exists in the Endpoint Data Loss Prevention (DLP) Module of the Netskope Client for Windows. This vulnerability allows an unprivileged user to exploit an out-of-bounds read in a driver, potentially causing a Blue Screen of Death (BSOD). The Endpoint DLP module must be enabled in the client configuration for the vulnerability to be exploited. This issue affects all Netskope Client versions prior to R136.1.
Netskope has released a security patch for this vulnerability. Users can update to version R136.1 or later. For those on earlier versions, the patch has been backported to R129.1.8 and above, R132.0.23 and above, and R135.1.0 and above. Instructions for downloading the updated client are available on the Netskope Support portal.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | New CVE Received | [email protected] |