CVE-2026-40954: Absolute Secure Access
Low severity, CVSS 3.7. EPSS: 0.3% chance of exploitation in the next 30 days.
CVE-2026-40954 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client
Affected products
- Absolute Secure Access: before 14.55 (fixed in 14.55)
Published 2026-07-15. Last modified 2026-07-16.