Absolute
Absolute Secure Access: vulnerabilidades y CVE
Absolute Secure Access tiene 58 vulnerabilidades publicadas, 34 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE58
Últimos 12 meses34
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-55402 | Alta (8.7) | 0.40% | — | 13 ago 2026 | CVE-2026-55402 is an out of bounds read vulnerability in Secure Access servers prior to version 14.57. Attackers with an ‘in the middle’ position can send specially crafted data to a server causing a persistent denial… |
| CVE-2026-55401 | Media (6.9) | 0.40% | — | 13 ago 2026 | CVE-2026-55401 is a null dereference vulnerability on the load-balancing sub-system of Secure Access servers prior to 14.57. Attackers can send an unauthenticated packet to a Secure Access server with load balancing… |
| CVE-2026-55400 | Media (6) | 0.37% | — | 13 ago 2026 | CVE-2026-55400 is an integer underflow in Secure Access servers prior to version 14.57. Attackers with an authenticated session can send specially crafted traffic to a server in a non-default configuration and cause a… |
| CVE-2026-55399 | Media (5.1) | 0.37% | — | 15 jul 2026 | CVE-2026-55399 is a resource exhaustion vulnerability in the Secure Access publisher prior to 14.55. Attackers with valid credentials to the Secure Access tunnel can create a non-persistent DoS against the publisher. |
| CVE-2026-55398 | Media (6.9) | 0.35% | — | 15 jul 2026 | CVE-2026-55398 is a memory management vulnerability in Secure Access clients and servers prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS… |
| CVE-2026-33445 | Alta (8.7) | 0.40% | — | 15 jul 2026 | CVE-2026-33445 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total control over the tunnel protocol can create a persistent DoS against the… |
| CVE-2026-33444 | Media (6.9) | 0.35% | — | 15 jul 2026 | CVE-2026-33444 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against the… |
| CVE-2026-40958 | Baja (2.3) | 0.38% | — | 15 jul 2026 | CVE-2026-40958 is a input validation error in Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client. |
| CVE-2026-40957 | Media (6.1) | 0.43% | — | 15 jul 2026 | o CVE-2026-40957 is a frameable content vulnerability in the Secure Access server login page prior to 14.55. Attackers with control of a malicious web site could use it to potentially steal credentials from an unwary… |
| CVE-2026-40956 | Baja (2.1) | 0.27% | — | 15 jul 2026 | CVE-2026-40956 is a memory disclosure vulnerability in Secure Access client versions prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can cause a small amount of random… |
| CVE-2026-40955 | Baja (2.1) | 0.32% | — | 15 jul 2026 | CVE-2026-40955 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a… |
| CVE-2026-40954 | Baja (2.1) | 0.32% | — | 15 jul 2026 | CVE-2026-40954 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a… |
| CVE-2026-40953 | Media (6.7) | 0.10% | — | 15 jul 2026 | CVE-2026-40953 is a heap overflow in the certificate parsing function of Secure Access clients prior to 14.55. Attackers with local access and administrator permissions can create a denial of service attack against the… |
| CVE-2026-40952 | Alta (8.5) | 0.14% | — | 15 jul 2026 | CVE-2026-40952 is a privilege misconfiguration in the Secure Access installer for the Windows client and server prior to version 14.55. Attackers with local access to the client or server can use it to elevate… |
| CVE-2026-33443 | Alta (7.1) | 0.37% | — | 15 jul 2026 | CVE-2026-33443 is a memory management error in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total control over the tunnel protocol can create a persistent DoS against the server. |
| CVE-2026-40951 | Media (6.8) | 0.13% | — | 30 abr 2026 | CVE-2026-40951 is a memory corruption vulnerability on Secure Access Windows clients prior to 14.50. Attackers with local control of the Windows client can send malformed data to an API and trigger a denial of service. |
| CVE-2026-40950 | Alta (7.1) | 0.42% | — | 30 abr 2026 | CVE-2026-40950 is a buffer overflow vulnerability in the Secure Access server prior to 14.50. Attackers with control of a modified client can send a specially crafted message to the server and cause a denial of service |
| CVE-2026-40949 | Media (6.8) | 0.14% | — | 30 abr 2026 | CVE-2026-40949 is a buffer overflow vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can use it to trigger a denial of service. |
| CVE-2026-33452 | Media (5.9) | 0.13% | — | 30 abr 2026 | CVE-2026-33452 is a buffer overflow vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can use it to ‘blue screen’ the system. |
| CVE-2026-33451 | Alta (8.5) | 0.15% | — | 30 abr 2026 | CVE-2026-33451 is an arbitrary read/write vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can send malformed data to an API and elevate their level of… |
| CVE-2026-33450 | Baja (2.3) | 0.26% | — | 30 abr 2026 | CVE-2026-33450 is an out of bounds read vulnerability in the Secure Access MacOS client prior to 14.50. Attackers with control of a modified server can send a malformed packet to the client causing a denial of service. |
| CVE-2026-33449 | Baja (2.3) | 0.40% | — | 30 abr 2026 | CVE-2026-33449 is a buffer overflow in a message handling function of the Secure Access client prior to 14.50. Attackers with control of a modified server can send a cryptographically valid message to the client,… |
| CVE-2026-33448 | Media (4.8) | 0.14% | — | 30 abr 2026 | CVE-2026-33448 is a format string vulnerability in the logging subsystem of Secure Access client for MacOS prior to 14.50. Attackers with control of a modified server can force the client to dump the contents of a small… |
| CVE-2026-33447 | Baja (2.3) | 0.44% | — | 30 abr 2026 | CVE-2026-33447 is a buffer overflow in a message parsing function of the Secure Access client prior to 14.50. Attackers with control of a modified server can send a special packet that can overwrite a small portion of… |
| CVE-2026-33446 | Baja (2.3) | 0.52% | — | 30 abr 2026 | CVE-2026-33446 is a buffer overflow in the authentication sub-system of the Secure Access client prior to 14.50. Attackers with control of a modified server can send a special packet that can overwrite a small portion… |
| CVE-2026-0519 | Media (4.6) | 0.14% | — | 17 ene 2026 | In Secure Access 12.70 and prior to 14.20, the logging subsystem may write an unredacted authentication token to logs under certain configurations. Any party with access to those logs could read the token and reuse it… |
| CVE-2026-0518 | Media (4.8) | 0.17% | — | 17 ene 2026 | CVE-2026-0518 is a cross-site scripting vulnerability in versions of Secure Access prior to 14.20. An attacker with administrative privileges can interfere with another administrator’s use of the console. |
| CVE-2026-0517 | Media (6) | 0.31% | — | 17 ene 2026 | CVE-2026-0517 is a denial-of-service vulnerability in versions of Secure Access Server prior to 14.20. An attacker can send a specially crafted packet to a server and cause the server to crash |
| CVE-2025-59596 | Media (6) | 0.20% | — | 4 nov 2025 | CVE-2025-59596 is a denial-of-service vulnerability in Secure Access Windows client versions 12.0 to 14.10 that is addressed in version 14.12. If a local networking policy is active, attackers on an adjacent network may… |
| CVE-2025-59595 | Alta (8.2) | 0.34% | — | 4 nov 2025 | CVE-2025-59595 is an internally discovered denial of service vulnerability in versions of Secure Access prior to 14.12. An attacker can send a specially crafted packet to a server in a non-default configuration and… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.