CVE-2025-14026

CVE-2025-14026: Vulnerable Python version used in Forcepoint One DLP Client

Vendor Forcepoint
Product Forcepoint One Endpoint (F1E)
Published January 6, 2026
Last update January 6, 2026

CVSS base score

What the vulnerability does

Description

Forcepoint One DLP Client, version 23.04.5642 (and possibly newer versions), includes a restricted version of Python 2.5.4 that prevents use of the ctypes library. ctypes is a foreign function interface (FFI) for Python, enabling calls to DLLs/shared libraries, memory allocation, and direct code execution. It was demonstrated that these restrictions could be bypassed.

Key dates

Disclosure timeline

January 6, 2026 CVE published
January 6, 2026 Record updated