Vulnerabilities
56 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-55402 | CVE-2026-55402 is an out of bounds read vulnerability in Secure Access servers prior to version 14.57. CVE-2026-55402 is an out of bounds read vulnerability in Secure Access servers prior to version 14.57. Attackers with an ‘in the middle’ position can send specially crafted data to a server causing a persistent denial of service. NVD description · AI analysis pending | 8.7 group max | <1% |
| — | ||
| CVE-2026-33445 | CVE-2026-33445 is a memory management vulnerability in Secure Access servers prior to 14.55. CVE-2026-33445 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total control over the tunnel protocol can create a persistent DoS against the server. NVD description · AI analysis pending | 8.7 group max | <1% |
| — | ||
| CVE-2026-33451 | CVE-2026-33451 is an arbitrary read/write vulnerability in the Secure Access Windows client prior to 14.50. CVE-2026-33451 is an arbitrary read/write vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can send malformed data to an API and elevate their level of privilege to system. NVD description · AI analysis pending | 8.5 group max | <1% |
| — | ||
| CVE-2026-0517 | CVE-2026-0517 is a denial-of-service vulnerability in versions of Secure Access Server prior to 14.20. CVE-2026-0517 is a denial-of-service vulnerability in versions of Secure Access Server prior to 14.20. An attacker can send a specially crafted packet to a server and cause the server to crash NVD description · AI analysis pending | 6.0 group max | <1% |
| — | ||
| CVE-2025-59595 +1 in the same advisory: …59596 | CVE-2025-59595 is an internally discovered denial of service vulnerability in versions of Secure Access prior to 14.12. CVE-2025-59595 is an internally discovered denial of service vulnerability in versions of Secure Access prior to 14.12. An attacker can send a specially crafted packet to a server in a non-default configuration and cause the server to crash. NVD description · AI analysis pending | 8.2 group max | <1% |
| — | ||
| CVE-2025-54088 | CVE-2025-54088 is an open-redirect vulnerability in Secure Access prior to version 14.10. CVE-2025-54088 is an open-redirect vulnerability in Secure Access prior to version 14.10. Attackers with access to the console can redirect victims to an arbitrary URL. The attack complexity is low, attack requirements are present, no privileges are required, and users must actively participate in the attack. Impact to confidentiality is low and there is no impact to integrity or availability. There are high severity impacts to confidentiality, integrity, availability in subsequent systems. NVD description · AI analysis pending | 5.5 group max | <1% |
| — | ||
| CVE-2025-49083 | CVE-2025-49083 is a vulnerability in the management console of Absolute Secure Access after version 12.00 and prior to version 13.56. CVE-2025-49083 is a vulnerability in the management console of Absolute Secure Access after version 12.00 and prior to version 13.56. Attackers with administrative access to the console can cause unsafe content to be deserialized and executed in the security context of the console. The attack complexity is low and there are no attack requirements. Privileges required are high and there is no user interaction required. The impact to confidentiality is low, impact to integrity is high and there is no impact to availability. The impact to the confidentiality and integrity of subsequent systems is low and there is no subsequent system impact to availability. NVD description · AI analysis pending | 7.0 group max | <1% |
| — | ||
| CVE-2025-49080 +1 in the same advisory: …49081 | There is a memory management vulnerability in Absolute Secure Access server versions 9.0 to 13.54. There is a memory management vulnerability in Absolute Secure Access server versions 9.0 to 13.54. Attackers with network access to the server can cause a Denial of Service by sending a specially crafted sequence of packets to the server. The attack complexity is low, there are no attack requirements, privileges, or user interaction required. Loss of availability is high; there is no impact on confidentiality or integrity. NVD description · AI analysis pending | 8.7 group max | <1% |
| — | ||
| CVE-2025-27703 | CVE-2025-27703 is a privilege escalation vulnerability in the management console of Absolute Secure Access prior to version 13.54. CVE-2025-27703 is a privilege escalation vulnerability in the management console of Absolute Secure Access prior to version 13.54. Attackers with administrative access to a specific subset of privileged features in the console can elevate their permissions to access additional features in the console. The attack complexity is low, there are no preexisting attack requirements; the privileges required are high, and there is no user interaction required. The impact to system confidentiality is low, the impact to system integrity is high and the impact to system availability is low. NVD description · AI analysis pending | 7.0 group max | <1% |
| — | ||
| CVE-2024-6364 | A vulnerability in Absolute Persistence® versions before 2.8 exists when it is not activated. A vulnerability in Absolute Persistence® versions before 2.8 exists when it is not activated. This may allow a skilled attacker with both physical access to the device, and full hostile network control, to initiate OS commands on the device. To remediate this vulnerability, update the device firmware to the latest available version. Please contact the device manufacturer for upgrade instructions or contact Absolute Security, see reference below. NVD description · AI analysis pending | 6.9 | <1% |
| — | ||
| CVE-2024-40873 | There is a cross-site scripting vulnerability in the Secure Access administrative console of Absolute Secure Access prior to version 13.07. There is a cross-site scripting vulnerability in the Secure Access administrative console of Absolute Secure Access prior to version 13.07. Attackers with system administrator permissions can interfere with another system administrator’s use of the publishing UI when the administrators are editing the same management object. The scope is unchanged, there is no loss of confidentiality. Impact to system availability is none, impact to system integrity is high. NVD description · AI analysis pending | 3.4 | <1% |
| — | ||
| CVE-2024-37350 | There is a cross-site scripting vulnerability in the policy management UI of Absolute Secure Access prior to version 13.06. There is a cross-site scripting vulnerability in the policy management UI of Absolute Secure Access prior to version 13.06. Attackers can interfere with a system administrator’s use of the policy management UI when the attacker convinces the victim administrator to follow a crafted link to the vulnerable component while the attacking administrator is authenticated to the console. The scope is unchanged, there is no loss of confidentiality. Impact to system integrity is high, impact to system availability is none. NVD description · AI analysis pending | 4.7 group max | <1% |
| — |