CVE-2026-11459

A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. Impacted is an unknown function in the library saappctl.sys of the component IOCTL Handler. The manipulation leads to information disclosure. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used.
Configurations

No configuration.

History

23 Jul 2026, 07:10

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de seguridad ha sido detectada en SecureAge CatchPulse hasta 10.9.1. Afectada es una función desconocida en la biblioteca saappctl.sys del componente Gestor IOCTL. La manipulación conduce a la revelación de información. Se requiere acceso local para abordar este ataque. El exploit ha sido revelado públicamente y puede ser utilizado. El proveedor fue contactado con antelación sobre esta revelación pero no respondió de ninguna manera.

12 Jun 2026, 18:16

Type Values Removed Values Added
Summary (en) A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. Impacted is an unknown function in the library saappctl.sys of the component IOCTL Handler. The manipulation leads to information disclosure. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. (en) A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. Impacted is an unknown function in the library saappctl.sys of the component IOCTL Handler. The manipulation leads to information disclosure. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used.

09 Jun 2026, 06:16

Type Values Removed Values Added
References
  • () https://github.com/Kalagious/SecureAgeExploit -

08 Jun 2026, 16:16

Type Values Removed Values Added
References
  • {'url': 'https://vandalsuidaho-my.sharepoint.com/:w:/g/personal/higg2059_vandals_uidaho_edu/IQBo2bcYM-FJTpon1vC0En0vAS3OerOp4Nf0EeZIU4u9mgY?e=XAT64X', 'source': 'cna@vuldb.com'}
  • () https://jordanhiggins.blog/catchpulse-antivirus-exploits/ -
Summary (en) A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.1. Impacted is an unknown function in the library saappctl.sys of the component IOCTL Handler. The manipulation leads to information disclosure. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. (en) A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. Impacted is an unknown function in the library saappctl.sys of the component IOCTL Handler. The manipulation leads to information disclosure. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

07 Jun 2026, 10:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-07 10:16

Updated : 2026-07-23 07:10


NVD link : CVE-2026-11459

Mitre link : CVE-2026-11459

CVE.ORG link : CVE-2026-11459


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-284

Improper Access Control