Cybersecuritynews Critical Symantec DLP Agent Vulnerability Enables Privilege Escalation
Article Content
- •CVE-2026-3991 allows low-privileged attackers to escalate privileges on Windows systems.
- •The vulnerability has a CVSS score of 7.8, indicating a high severity level.
- •Broadcom has released patches as of March 30, 2026, which should be applied immediately.
A high-severity vulnerability, tracked as CVE-2026-3991, has been identified in the Symantec Data Loss Prevention (DLP) Agent for Windows. Discovered by security researcher Manuel Feifel, this flaw allows low-privileged local attackers to escalate their privileges to the highest level on affected systems. The vulnerability carries a CVSS score of 7.8, indicating a significant risk of deep system compromise. Broadcom has released patches to address this issue as of March 30, 2026. Organizations using the Symantec DLP Agent should prioritize applying these patches to mitigate potential attacks. The flaw affects Windows systems running the DLP Agent, making it critical for enterprises reliant on this software. Immediate action is recommended to prevent exploitation. The vulnerability was published on March 30, 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track TA416, Broadcom and CVE-2026-3991 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…