VendorsAbsolutesecure_accessall versions
Vulnerabilities

Absolute Secure Access

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

54CVEs
CVE-2026-33446
Buffer overflow in client authentication prior to version 14.50
Published 2026-04-30 · Analyzed
9.8EPSS 0.005
CVE-2026-33447
CVE-2026-33447 is a buffer overflow in a message parsing function of the Secure Access client prior to 14.50. Attackers with control of a modified server can send a special packet that can overwrite a small portion of memory conceivably leading to memory corruption or denial of service.
Published 2026-04-30 · Analyzed
9.8EPSS 0.004
CVE-2025-49084
Elevation of privilege vulnerability in the Secure Access administrative console of Absolute Secure Access prior to version 13.56
Published 2025-07-30 · Analyzed
9.1EPSS 0.003
CVE-2026-33445
Memory management vulnerability in Secure Access servers
Published 2026-07-15 · Analyzed
8.7EPSS 0.004
CVE-2026-55402
CVE-2026-55402 is an out of bounds read vulnerability in Secure Access servers prior to version 14.57. Attackers with an ‘in the middle’ position can send specially crafted data to a server causing a persistent denial of service.
Published 2026-08-13 · Analyzed
8.7EPSS 0.004
CVE-2025-49080
Memory management vulnerability in Absolute Secure Access server versions 9.0 to 13.54
Published 2025-06-12 · Analyzed
8.7EPSS 0.004
CVE-2026-33451
Arbitrary read/write vulnerability in Windows clients prior to 14.50
Published 2026-04-30 · Analyzed
8.5EPSS 0.002
CVE-2026-40952
Privilge misconfiguration in Secure Access installers
Published 2026-07-15 · Modified
8.5EPSS 0.001
CVE-2025-59595
CVE-2025-59595 is an internally discovered denial of service vulnerability in versions of Secure Access prior to 14.12. An attacker can send a specially crafted packet to a server in a non-default configuration and cause the server to crash.
Published 2025-11-04 · Analyzed
8.2EPSS 0.003
CVE-2026-40957
Frameable content vulnerability in the Secure Access server login page
Published 2026-07-15 · Modified
7.5EPSS 0.004
CVE-2026-33449
Message handler buffer overflow in clients prior to 14.50
Published 2026-04-30 · Analyzed
7.5EPSS 0.004
CVE-2026-0517
Denial of Service in Secure Access Servers Prior to 14.20.
Published 2026-01-17 · Analyzed
7.5EPSS 0.003
CVE-2025-49083
Data deserialization vulnerability in the Secure Access administrative console of Absolute Secure Access prior to version 13.56
Published 2025-07-30 · Analyzed
7.2EPSS 0.004
CVE-2026-40950
Buffer overflow in the Secure Access server prior to 14.50
Published 2026-04-30 · Analyzed
7.1EPSS 0.004
CVE-2026-33443
Memory management error in Secure Access servers prior to 14.55
Published 2026-07-15 · Modified
7.1EPSS 0.004
CVE-2025-27703
Privilege escalation in the management console of Absolute Secure Access prior to version 13.54
Published 2025-05-28 · Analyzed
7.0EPSS 0.003
CVE-2025-49081
Input validation vulnerability in the Secure Access prior to version 13.55
Published 2025-06-12 · Analyzed
6.9EPSS 0.005
CVE-2026-55401
CVE-2026-55401 is a null dereference vulnerability on the load-balancing sub-system of Secure Access servers prior to 14.57. Attackers can send an unauthenticated packet to a Secure Access server with load balancing enabled, which results in the internal load balancer crashing. After a successful attack, the Secure Access server is still able to accept connections and is still able to issue a failover to connected clients. ‍ https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L
Published 2026-08-13 · Analyzed
6.9EPSS 0.004
CVE-2026-55398
Memory management vulnerability in Secure Access clients
Published 2026-07-15 · Analyzed
6.9EPSS 0.004
CVE-2026-33444
Memory management vulnerability in Secure Access servers
Published 2026-07-15 · Analyzed
6.9EPSS 0.004
CVE-2025-27702
Permissions bypass in the management console of Absolute Secure Access prior to version 13.54
Published 2025-05-28 · Analyzed
6.9EPSS 0.003
CVE-2026-40949
Buffer overflow in Windows clients prior to 14.50
Published 2026-04-30 · Analyzed
6.8EPSS 0.001
CVE-2026-40951
Memory corruption in Secure Access Windows clients prior to 14.50
Published 2026-04-30 · Analyzed
6.8EPSS 0.001
CVE-2026-40953
Heap overflow in Secure Access clients
Published 2026-07-15 · Modified
6.7EPSS 0.001
CVE-2026-55400
CVE-2026-55400 is an integer underflow in Secure Access servers prior to version 14.57. Attackers with an authenticated session can send specially crafted traffic to a server in a non-default configuration and cause a persistent denial of service.
Published 2026-08-13 · Analyzed
6.5EPSS 0.004
CVE-2024-37350
Cross-site scripting vulnerability in the Absolute Secure Access administrative console prior to 13.06
Published 2024-06-20 · Modified
6.5EPSS 0.003
CVE-2025-59596
CVE-2025-59596 is a denial-of-service vulnerability in Secure Access Windows client versions 12.0 to 14.10 that is addressed in version 14.12. If a local networking policy is active, attackers on an adjacent network may be able to send a crafted packet and cause the client system to crash.
Published 2025-11-04 · Analyzed
6.5EPSS 0.002
CVE-2025-54088
Open Redirect in Secure Access prior to 14.10
Published 2025-10-02 · Analyzed
6.1EPSS 0.002
CVE-2026-33452
Buffer overflow in Windows clients prior to 14.50
Published 2026-04-30 · Analyzed
5.9EPSS 0.001
CVE-2026-33450
Out of bounds read in Secure Access MacOS clients prior to 14.50
Published 2026-04-30 · Analyzed
5.5EPSS 0.003
CVE-2024-37343
Cross-site scripting vulnerability in the Absolute Secure Access administrative console prior to 13.06
Published 2024-06-20 · Modified
5.4EPSS 0.002
CVE-2024-37345
Cross-site scripting vulnerability in the Absolute Secure Access administrative console prior to 13.06
Published 2024-06-20 · Modified
5.4EPSS 0.002
CVE-2025-54086
Excess Permissions in Warehouse
Published 2025-10-02 · Analyzed
5.3EPSS 0.002
CVE-2026-55399
Resource exhaustion vulnerability in the Secure Access publisher
Published 2026-07-15 · Analyzed
5.1EPSS 0.004
CVE-2025-49082
Permissions bypass vulnerability in the Secure Access administrative console of Absolute Secure Access prior to version 13.56
Published 2025-07-30 · Analyzed
5.1EPSS 0.002
CVE-2025-54085
Elevation of privilege vulnerability in the Secure Access administrative console of Absolute Secure Access prior to version 13.56
Published 2025-07-30 · Analyzed
5.1EPSS 0.002
CVE-2024-37346
Insufficient input validation vulnerability in the Absolute Secure Access Warehouse prior to 13.06
Published 2024-06-20 · Modified
4.9EPSS 0.004
CVE-2026-0518
XSS in Secure Access Consoles prior to 14.20
Published 2026-01-17 · Analyzed
4.8EPSS 0.002
CVE-2026-33448
Format string vulnerability in MacOS clients prior to 14.50
Published 2026-04-30 · Analyzed
4.8EPSS 0.001
CVE-2025-27706
Cross-site scripting vulnerability in the Secure Access administrative console of Absolute Secure Access prior to version 13.54
Published 2025-05-28 · Analyzed
4.6EPSS 0.002
1 / 2Next →