CVE-2026-40953: Absolute Secure Access

Medium severity, CVSS 4.4. EPSS: 0.1% chance of exploitation in the next 30 days.

CVE-2026-40953 is a heap overflow in the certificate parsing function of Secure Access clients prior to 14.55. Attackers with local access and administrator permissions can create a denial of service attack against the client over which they have control.

Affected products

  • Absolute Secure Access: before 14.55 (fixed in 14.55)

Published 2026-07-15. Last modified 2026-07-16.