Skip to content
Critical Symantec DLP Agent Vulnerability Enables Privilege Escalation

Critical Symantec DLP Agent Vulnerability Enables Privilege Escalation

First seen 2 Apr 2026, 07:31 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •April 3, 2026 at 07:15 UTC
  • •CVE-2026-3991 allows low-privileged attackers to escalate privileges on Windows systems.
  • •The vulnerability has a CVSS score of 7.8, indicating a high severity level.
  • •Broadcom has released patches as of March 30, 2026, which should be applied immediately.

A high-severity vulnerability, tracked as CVE-2026-3991, has been identified in the Symantec Data Loss Prevention (DLP) Agent for Windows. Discovered by security researcher Manuel Feifel, this flaw allows low-privileged local attackers to escalate their privileges to the highest level on affected systems. The vulnerability carries a CVSS score of 7.8, indicating a significant risk of deep system compromise. Broadcom has released patches to address this issue as of March 30, 2026. Organizations using the Symantec DLP Agent should prioritize applying these patches to mitigate potential attacks. The flaw affects Windows systems running the DLP Agent, making it critical for enterprises reliant on this software. Immediate action is recommended to prevent exploitation. The vulnerability was published on March 30, 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 190d ago How this analysis works

Timeline

2026-03-30
CVE-2026-3991 published
2026-03-30
Patches released by Broadcom to address the vulnerability
2026-04-02
Articles report on the vulnerability and its implications

More articles in this cluster (3)

Following this threat?

Track TA416, Broadcom and CVE-2026-3991 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed