logo

CVE-2025-14026: Forcepoint DLP Flaw Lets Attackers Unchain Restricted Python

ID: fdde5280-50c1-5d84-ae5a-fb15a1287c01

STIX ID: report--fdde5280-50c1-5d84-ae5a-fb15a1287c01

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-01-07

Date Updated: 2026-04-22

Author: Ddos

...
...

A high-severity vulnerability (CVE-2025-14026, CVSS 7.8) was disclosed in the Forcepoint One DLP Client where a bundled legacy Python 2.5.4 runtime had its ctypes FFI removed as a mitigation but can be reconstructed by an attacker supplying compiled dependencies and patching ctypes.pyd, restoring the ability to execute arbitrary shellcode or DLLs. Exploitation could let attackers bypass DLP enforcement, disable monitoring, or alter client behavior on endpoints; Forcepoint fixed the issue by removing the vulnerable Python runtime in endpoint builds after version 23.11 and advises immediate upgrades.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.