CVE-2026-16174
Last modified
CVE-2026-16174 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. Netskope was notified about a potential gap in Netskope Endpoint DLP (EPDLP) running on Windows systems. Successful exploitation of the gap could potentially allow a privileged user to send a crafted message to the EPDLP process port to trigger an integer overflow, leading to memory corruption.
Description
Netskope was notified about a potential gap in Netskope Endpoint DLP (EPDLP) running on Windows systems. Successful exploitation of the gap could potentially allow a privileged user to send a crafted message to the EPDLP process port to trigger an integer overflow, leading to memory corruption. Successful exploitation would require the EPDLP module to be enabled in the client configuration, and that Memory Integrity is disabled. A successful exploit could potentially result in a denial-of-service, arbitrary code execution, or privilege escalation on the local machine.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Netskope | Endpoint DLP | < 141.0 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-16174?
How severe is CVE-2026-16174?
How do I fix CVE-2026-16174?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-16156A security flaw has been discovered in SourceCodester Class …3.5
- CVE-2026-16157Duplicati v2.3.0.1 backup software gives Authenticated Users…7.8
- CVE-2026-16158Impact: @fastify/reply-from versions from 8.3.1 up to but no…10
- CVE-2026-1616The $uri$args concatenation in nginx configuration file pres…7.5
- CVE-2026-1617Improper neutralization of special elements used in an SQL c…9.8
- CVE-2026-16172Netskope was notified of an out-of-bounds heap read affectin…6
- CVE-2026-1618Authentication Bypass Using an Alternate Path or Channel vul…8.8
- CVE-2026-16180IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12…5.7
- CVE-2026-16184IBM WebSphere Application Server 9.0, and 8.5 could allow a …9.8
- CVE-2026-1619Authorization Bypass Through User-Controlled Key vulnerabili…8.3
- CVE-2026-16192IBM WebSphere Application Server - Liberty 17.0.0.3 through …6.5
- CVE-2026-16194A vulnerability was determined in zhayujie CowAgent up to 2.…6.3
Are you affected by CVE-2026-16174?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
