CVE-2026-40955: Absolute Secure Access

Low severity, CVSS 3.7. EPSS: 0.3% chance of exploitation in the next 30 days.

CVE-2026-40955 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client.

Affected products

  • Absolute Secure Access: before 14.55 (fixed in 14.55)

Published 2026-07-15. Last modified 2026-07-16.