CVE-2026-40954
is an integer underflow vulnerability in the traffic parsing function of Secure
Access clients prior to 14.55. Attackers with intimate knowledge of and total
control over the tunnel protocol can create a non-persistent DoS against their
client
References
| Link | Resource |
|---|---|
| https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2026-40954 | Vendor Advisory |
Configurations
History
16 Jul 2026, 02:56
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2026-40954 - Vendor Advisory | |
| First Time |
Absolute secure Access
Absolute |
|
| CWE | CWE-191 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 3.7 |
| CPE | cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:* |
15 Jul 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-15 20:16
Updated : 2026-07-16 14:16
NVD link : CVE-2026-40954
Mitre link : CVE-2026-40954
CVE.ORG link : CVE-2026-40954
JSON object : View
Products Affected
absolute
- secure_access
CWE
CWE-191
Integer Underflow (Wrap or Wraparound)
