← Back

Absolute

absolute

56 CVEs • 4 products

Products (4)

Click to collapse
Toggle

CVEs (56)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Absolute
1Secure Access
Jul 16, 2026
Jul 15, 2026
5.1 MEDIUM· v4
4.3 MEDIUM· v3
N/A· v2
CVE-2026-55399 is a resource exhaustion vulnerability in the Secure Access publisher prior to 14.55. Attackers with valid credentials to the Secure Access tunnel can create a non-persistent DoS against the publisher.
1Absolute
1Secure Access
Jul 16, 2026
Jul 15, 2026
6.9 MEDIUM· v4
3.7 LOW· v3
N/A· v2
CVE-2026-55398 is a memory management vulnerability in Secure Access clients and servers prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS aga...Show more
CVE-2026-55398 is a memory management vulnerability in Secure Access clients and servers prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against the server.Show less
1Absolute
1Secure Access
Jul 16, 2026
Jul 15, 2026
8.7 HIGH· v4
5.9 MEDIUM· v3
N/A· v2
CVE-2026-33445 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total control over the tunnel protocol can create a persistent DoS against the serv...Show more
CVE-2026-33445 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total control over the tunnel protocol can create a persistent DoS against the server.Show less
1Absolute
1Secure Access
Jul 16, 2026
Jul 15, 2026
6.9 MEDIUM· v4
3.7 LOW· v3
N/A· v2
CVE-2026-33444 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against the ser...Show more
CVE-2026-33444 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against the server.Show less
1Absolute
1Secure Access
Jul 16, 2026
Jul 15, 2026
2.3 LOW· v4
3.7 LOW· v3
N/A· v2
CVE-2026-40958 is a input validation error in Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client.
1Absolute
1Secure Access
Jul 16, 2026
Jul 15, 2026
6.1 MEDIUM· v4
7.5 HIGH· v3
N/A· v2
o   CVE-2026-40957 is a frameable content vulnerability in the Secure Access server login page prior to 14.55. Attackers with control of a malicious web site could use it to potentially steal credentials from an unwary a...Show more
o   CVE-2026-40957 is a frameable content vulnerability in the Secure Access server login page prior to 14.55. Attackers with control of a malicious web site could use it to potentially steal credentials from an unwary administrator.Show less
1Absolute
1Secure Access
Jul 16, 2026
Jul 15, 2026
2.1 LOW· v4
3.7 LOW· v3
N/A· v2
CVE-2026-40956 is a memory disclosure vulnerability in Secure Access client versions prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can cause a small amount of random memo...Show more
CVE-2026-40956 is a memory disclosure vulnerability in Secure Access client versions prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can cause a small amount of random memory to leak.Show less
1Absolute
1Secure Access
Jul 16, 2026
Jul 15, 2026
2.1 LOW· v4
3.7 LOW· v3
N/A· v2
CVE-2026-40955 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a n...Show more
CVE-2026-40955 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client.Show less
1Absolute
1Secure Access
Jul 16, 2026
Jul 15, 2026
2.1 LOW· v4
3.7 LOW· v3
N/A· v2
CVE-2026-40954 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a n...Show more
CVE-2026-40954 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their clientShow less
1Absolute
1Secure Access
Jul 16, 2026
Jul 15, 2026
6.7 MEDIUM· v4
4.4 MEDIUM· v3
N/A· v2
CVE-2026-40953 is a heap overflow in the certificate parsing function of Secure Access clients prior to 14.55. Attackers with local access and administrator permissions can create a denial of service attack against the c...Show more
CVE-2026-40953 is a heap overflow in the certificate parsing function of Secure Access clients prior to 14.55. Attackers with local access and administrator permissions can create a denial of service attack against the client over which they have control.Show less
1Absolute
1Secure Access
Jul 16, 2026
Jul 15, 2026
8.5 HIGH· v4
7.8 HIGH· v3
N/A· v2
CVE-2026-40952 is a privilege misconfiguration in the Secure Access installer for the Windows client and server prior to version 14.55. Attackers with local access to the client or server can use it to elevate privileges...Show more
CVE-2026-40952 is a privilege misconfiguration in the Secure Access installer for the Windows client and server prior to version 14.55. Attackers with local access to the client or server can use it to elevate privileges to Administrator when Secure Access is installed in a non-default location.Show less
1Absolute
1Secure Access
Jul 16, 2026
Jul 15, 2026
7.1 HIGH· v4
5.9 MEDIUM· v3
N/A· v2
CVE-2026-33443 is a memory management error in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total control over the tunnel protocol can create a persistent DoS against the server.
1Absolute
1Secure Access
Jun 17, 2026
Apr 30, 2026
6.8 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
CVE-2026-40951 is a memory corruption vulnerability on Secure Access Windows clients prior to 14.50. Attackers with local control of the Windows client can send malformed data to an API and trigger a denial of service...Show more
CVE-2026-40951 is a memory corruption vulnerability on Secure Access Windows clients prior to 14.50. Attackers with local control of the Windows client can send malformed data to an API and trigger a denial of service.Show less
1Absolute
1Secure Access
Jun 17, 2026
Apr 30, 2026
7.1 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
CVE-2026-40950 is a buffer overflow vulnerability in the Secure Access server prior to 14.50. Attackers with control of a modified client can send a specially crafted message to the server and cause a denial of servic...Show more
CVE-2026-40950 is a buffer overflow vulnerability in the Secure Access server prior to 14.50. Attackers with control of a modified client can send a specially crafted message to the server and cause a denial of serviceShow less
1Absolute
1Secure Access
Jun 17, 2026
Apr 30, 2026
6.8 MEDIUM· v4
4.4 MEDIUM· v3
N/A· v2
CVE-2026-40949 is a buffer overflow vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can use it to trigger a denial of service.
1Absolute
1Secure Access
Jun 17, 2026
Apr 30, 2026
5.9 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
CVE-2026-33452 is a buffer overflow vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can use it to ‘blue screen’ the system.
1Absolute
1Secure Access
Jun 17, 2026
Apr 30, 2026
8.5 HIGH· v4
7.8 HIGH· v3
N/A· v2
CVE-2026-33451 is an arbitrary read/write vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can send malformed data to an API and elevate their level...Show more
CVE-2026-33451 is an arbitrary read/write vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can send malformed data to an API and elevate their level of privilege to system.Show less
1Absolute
1Secure Access
Jun 17, 2026
Apr 30, 2026
2.3 LOW· v4
5.5 MEDIUM· v3
N/A· v2
CVE-2026-33450 is an out of bounds read vulnerability in the Secure Access MacOS client prior to 14.50. Attackers with control of a modified server can send a malformed packet to the client causing a denial of service...Show more
CVE-2026-33450 is an out of bounds read vulnerability in the Secure Access MacOS client prior to 14.50. Attackers with control of a modified server can send a malformed packet to the client causing a denial of service.Show less
1Absolute
1Secure Access
Jun 17, 2026
Apr 30, 2026
2.3 LOW· v4
7.5 HIGH· v3
N/A· v2
CVE-2026-33449 is a buffer overflow in a message handling function of the Secure Access client prior to 14.50. Attackers with control of a modified server can send a cryptographically valid message to the client, over...Show more
CVE-2026-33449 is a buffer overflow in a message handling function of the Secure Access client prior to 14.50. Attackers with control of a modified server can send a cryptographically valid message to the client, overwriting a small portion of memory conceivably leading to a denial of service.Show less
1Absolute
1Secure Access
Jun 17, 2026
Apr 30, 2026
4.8 MEDIUM· v4
3.3 LOW· v3
N/A· v2
CVE-2026-33448 is a format string vulnerability in the logging subsystem of Secure Access client for MacOS prior to 14.50. Attackers with control of a modified server can force the client to dump the contents of a sma...Show more
CVE-2026-33448 is a format string vulnerability in the logging subsystem of Secure Access client for MacOS prior to 14.50. Attackers with control of a modified server can force the client to dump the contents of a small portion of memory to the log files potentially revealing secrets.Show less