{"record":"Forcepoint DLP evidence record","url":"https://nexalign.io/vendors/forcepoint-dlp","vendor":{"slug":"forcepoint-dlp","name":"Forcepoint DLP","domain":"forcepoint.com","category":"data-security","categoryLabel":"Data security"},"lastChecked":"2026-07-18T10:20:51.303Z","coverage":{"earliest":"2019-10-23T18:57:51.000Z","latest":"2026-07-18T10:20:51.303Z"},"terms":{"isRanking":false,"isRating":false,"statesSuitability":false,"note":"This is a record of what public sources hold about a named company. It states no ranking, no rating and no suitability verdict, and none may be derived from it. An absent or small record means the public registers publish little under that name; it is not evidence that a product is secure. A larger advisory count generally reflects wider deployment and more scrutiny rather than a weaker product.","licence":"https://nexalign.io/vendors#licence","corrections":"info@nexalign.io"},"totals":{"evidenceItems":11,"kindsOfSource":4,"attributedAdvisories":4,"knownExploited":0,"registerEntriesNotAttributable":0,"practitionerThreads":0,"independentItems":2,"vendorPublishedItems":0,"shareFromSourcesTheVendorDoesNotControl":1},"sources":[{"source":"European Vulnerability Database","operator":"ENISA, European Union","classification":"authoritative","items":3,"latest":"2026-01-06T14:45:29.000Z"},{"source":"CERT-Bund security advisories","operator":"BSI, Federal Republic of Germany","classification":"authoritative","items":1,"latest":"2026-03-12T11:11:38.209Z"},{"source":"National Vulnerability Database","operator":"NIST, United States Department of Commerce","classification":"authoritative","items":1,"latest":"2026-01-06T15:15:42.057Z"},{"source":"Analyst, review and reference sources","operator":"Recognised analysts, review marketplaces and technology press","classification":"independent","items":6,"latest":"2026-07-18T10:20:51.303Z"}],"advisories":{"shown":4,"total":4,"truncated":false,"items":[{"id":"WID-SEC-2026-0703","description":"Affected products: Forcepoint Next Generation Firewall","severity":"medium","cvss":7.8,"knownExploited":false,"date":"2026-03-12T11:11:38.209Z","sources":["https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-0703"]},{"id":"CVE-2025-14026","description":"Forcepoint One DLP Client, version 23.04.5642 (and possibly newer versions), includes a restricted version of Python 2.5.4 that prevents use of the ctypes library.","severity":"high","cvss":7.8,"knownExploited":false,"date":"2026-01-06T15:15:42.057Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2025-14026","https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-1032"]},{"id":"CVE-2022-1700","description":"Improper Restriction of XML External Entity Reference ('XXE') vulnerability in the Policy Engine of Forcepoint Data Loss Prevention (DLP), which is also leveraged by Forcepoint One Endpoint…","severity":"high","cvss":7.5,"knownExploited":false,"date":"2022-09-12T18:07:05.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-24985"]},{"id":"CVE-2019-6144","description":"This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint (versions 19.04 through 19.08) and bypass DLP and Web protection.","severity":null,"cvss":null,"knownExploited":false,"date":"2019-10-23T18:57:51.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-15711"]}]},"practitionerThreads":{"shown":0,"total":0,"truncated":false,"items":[]},"independentCoverage":{"shown":2,"total":2,"truncated":false,"items":[{"title":"Forcepoint DLP Reviews & Ratings 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/product/forcepoint-dlp","date":null},{"title":"Forcepoint DLP vs Fortra DLP 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/market/data-loss-prevention/compare/product/forcepoint-dlp-vs-fortras-digital-guardian","date":null}]},"vendorPublished":{"shown":0,"total":0,"truncated":false,"items":[]},"openQuestions":["No public practitioner discussion naming Forcepoint DLP was found in the indexed threads. Operational experience with this product is not represented in this record.","Pricing, contract terms, notice periods and support commitments are not part of any public register. They come from the vendor and belong in a negotiation record.","Certification status such as ISO 27001, SOC 2 or BSI C5 has to be checked against the current certificate and its stated scope. A valid certificate can still exclude the product being bought."]}