InfoGuard Labs[verified]@InfoGuard_LabsDisclosure
The post announces CVE-2026-3991, a local privilege escalation in Symantec DLP Agent via a hardcoded OpenSSL path, noting that it allows a SYSTEM shell, but offers no PoC, exploit code, patch notice, or active exploitation details.
ThreatCluster[verified]@threatclusterPatch
The announcement details a local privilege escalation vulnerability (CVE‑2026‑3991) in Symantec DLP Agent for Windows, includes its CVSS score, and notes that Broadcom released patches on March 30, 2026.
Israel[verified]@f1tym1Disclosure
The Symantec DLP Agent for Windows has a newly disclosed high‑severity privilege‑escalation flaw (CVE‑2026‑3991) that allows local low‑privileged users to gain higher rights; no PoC, exploit, or active exploitation has been reported.
Syed Aquib[verified]@syedaquib77Disclosure
Symantec DLP Agent for Windows (CVE‑2026‑3991) suffers a local privilege escalation via a crafted OpenSSL config that triggers a DLL side‑load, enabling SYSTEM‑level execution; patches are available and should be applied immediately.
Syed Aquib[verified]@syedaquib77Patch
Symantec DLP Agent local privilege escalation CVE‑2026‑3991 is disclosed with high severity; patches are available and should be applied immediately to mitigate the risk.
Syed Aquib[verified]@syedaquib77Patch
CVE-2026-3991 is a high‑severity local privilege escalation flaw in Symantec DLP agents with no patch yet but vendor updates and mitigation measures are detailed.
iototsecnews@iototsecnewsDisclosure
The article discusses a recently fixed Symantec DLP Agent vulnerability (CVE‑2026‑3991) that permits privilege escalation via outdated file paths, urging teams to exercise caution.
CERT-PY@CERTpyDisclosure
The post announces a new vulnerability (CVE-2026-3991) affecting Broadcom products and links to further information, but provides no technical, exploit, or mitigation details.