CVE-2026-40957: Absolute Secure Access

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

o   CVE-2026-40957 is a frameable content vulnerability in the Secure Access server login page prior to 14.55. Attackers with control of a malicious web site could use it to potentially steal credentials from an unwary administrator.

Affected products

  • Absolute Secure Access: before 14.55 (fixed in 14.55)

Published 2026-07-15. Last modified 2026-07-16.