Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
194 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.7) | 0.40% | — | Absolute Secure Access | 13/8/2026 | 4/9/2026 | CVE-2026-55402 is an out of bounds read vulnerability in Secure Access servers prior to version 14.57. Attackers with an ‘in the middle’ position can send specially crafted data to a server causing a persistent denial of service. | |
| Analizada | Media (6.9) | 0.40% | — | Absolute Secure Access | 13/8/2026 | 4/9/2026 | CVE-2026-55401 is a null dereference vulnerability on the load-balancing sub-system of Secure Access servers prior to 14.57. Attackers can send an unauthenticated packet to a Secure Access server with load balancing enabled, which results in the internal load balancer crashing. After a successful attack, the Secure… | |
| Analizada | Media (6) | 0.37% | — | Absolute Secure Access | 13/8/2026 | 4/9/2026 | CVE-2026-55400 is an integer underflow in Secure Access servers prior to version 14.57. Attackers with an authenticated session can send specially crafted traffic to a server in a non-default configuration and cause a persistent denial of service. | |
| Analizada | Media (5.1) | 0.37% | — | Absolute Secure Access | 15/7/2026 | 16/7/2026 | CVE-2026-55399 is a resource exhaustion vulnerability in the Secure Access publisher prior to 14.55. Attackers with valid credentials to the Secure Access tunnel can create a non-persistent DoS against the publisher. | |
| Analizada | Media (6.9) | 0.35% | — | Absolute Secure Access | 15/7/2026 | 16/7/2026 | CVE-2026-55398 is a memory management vulnerability in Secure Access clients and servers prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against the server. | |
| Analizada | Alta (8.7) | 0.40% | — | Absolute Secure Access | 15/7/2026 | 16/7/2026 | CVE-2026-33445 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total control over the tunnel protocol can create a persistent DoS against the server. | |
| Analizada | Media (6.9) | 0.35% | — | Absolute Secure Access | 15/7/2026 | 16/7/2026 | CVE-2026-33444 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against the server. | |
| Modificada | Baja (2.3) | 0.38% | — | Absolute Secure Access | 15/7/2026 | 16/7/2026 | CVE-2026-40958 is a input validation error in Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client. | |
| Modificada | Media (6.1) | 0.43% | — | Absolute Secure Access | 15/7/2026 | 16/7/2026 | o CVE-2026-40957 is a frameable content vulnerability in the Secure Access server login page prior to 14.55. Attackers with control of a malicious web site could use it to potentially steal credentials from an unwary administrator. | |
| Modificada | Baja (2.1) | 0.27% | — | Absolute Secure Access | 15/7/2026 | 16/7/2026 | CVE-2026-40956 is a memory disclosure vulnerability in Secure Access client versions prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can cause a small amount of random memory to leak. | |
| Modificada | Baja (2.1) | 0.32% | — | Absolute Secure Access | 15/7/2026 | 16/7/2026 | CVE-2026-40955 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client. | |
| Modificada | Baja (2.1) | 0.32% | — | Absolute Secure Access | 15/7/2026 | 16/7/2026 | CVE-2026-40954 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client | |
| Modificada | Media (6.7) | 0.10% | — | Absolute Secure Access | 15/7/2026 | 16/7/2026 | CVE-2026-40953 is a heap overflow in the certificate parsing function of Secure Access clients prior to 14.55. Attackers with local access and administrator permissions can create a denial of service attack against the client over which they have control. | |
| Modificada | Alta (8.5) | 0.14% | — | Absolute Secure Access | 15/7/2026 | 16/7/2026 | CVE-2026-40952 is a privilege misconfiguration in the Secure Access installer for the Windows client and server prior to version 14.55. Attackers with local access to the client or server can use it to elevate privileges to Administrator when Secure Access is installed in a non-default location. | |
| Modificada | Alta (7.1) | 0.37% | — | Absolute Secure Access | 15/7/2026 | 16/7/2026 | CVE-2026-33443 is a memory management error in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total control over the tunnel protocol can create a persistent DoS against the server. | |
| Pendiente de análisis | Media (6.8) | 0.18% | — | Citrix Secure Access ClientAI | 14/7/2026 | 15/7/2026 | Out-of-bounds read vulnerability in Citrix Citrix Secure Access Client for Windows. This issue affects Citrix Secure Access Client for Windows: before 26.6.1.20. | |
| Pendiente de análisis | Alta (8.5) | 0.17% | — | Citrix Secure Access ClientAICitrix Endpoint Analysis ClientAI | 14/7/2026 | 15/7/2026 | Improper Privilege Management vulnerability in Citrix Secure Access Client for Windows, Citrix Citrix Endpoint Analysis Client for Windows. This issue affects Secure Access Client for Windows: before 26.6.1.20; Citrix Endpoint Analysis Client for Windows: before 26. 5.1.7. | |
| Analizada | Alta (7.5) | 0.55% | — | Microsoft Global Secure Access | 22/5/2026 | 23/7/2026 | Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 1.2% | — | Ivanti Secure Access Client | 22/5/2026 | 23/7/2026 | An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arbitrary code. | |
| Analizada | Alta (7) | 0.38% | — | Ivanti Secure Access Client | 12/5/2026 | 17/6/2026 | A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges to SYSTEM | |
| Analizada | Media (4.4) | 0.24% | — | Ivanti Secure Access Client | 12/5/2026 | 17/6/2026 | An incorrect permission assignment for critical resource of Ivanti Secure Access Client before 22.8R6 allows a local authenticated user to read or modify sensitive log data via write access to a shared memory section. | |
| Analizada | Media (6.8) | 0.13% | — | Absolute Secure Access | 30/4/2026 | 17/6/2026 | CVE-2026-40951 is a memory corruption vulnerability on Secure Access Windows clients prior to 14.50. Attackers with local control of the Windows client can send malformed data to an API and trigger a denial of service. | |
| Analizada | Alta (7.1) | 0.42% | — | Absolute Secure Access | 30/4/2026 | 17/6/2026 | CVE-2026-40950 is a buffer overflow vulnerability in the Secure Access server prior to 14.50. Attackers with control of a modified client can send a specially crafted message to the server and cause a denial of service | |
| Analizada | Media (6.8) | 0.14% | — | Absolute Secure Access | 30/4/2026 | 17/6/2026 | CVE-2026-40949 is a buffer overflow vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can use it to trigger a denial of service. | |
| Analizada | Media (5.9) | 0.13% | — | Absolute Secure Access | 30/4/2026 | 17/6/2026 | CVE-2026-33452 is a buffer overflow vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can use it to ‘blue screen’ the system. |