VYPR

Secure Access

by Absolute

CVEs (58)

  • CVE-2025-54089LowOct 2, 2025
    risk 0.22cvss 3.4epss 0.00

    CVE-2025-54089 is a cross-site scripting vulnerability in versions of secure access prior to 14.10. Attackers with administrative access to the console can interfere with another administrator’s access to the console. The attack complexity is low; there are no attack…

  • CVE-2025-27706LowMay 28, 2025
    risk 0.22cvss 3.4epss 0.00

    CVE-2025-27706 is a cross-site scripting vulnerability in the management console of Absolute Secure Access prior to version 13.54. Attackers with system administrator permissions can interfere with another system administrator’s use of the management console when the second…

  • CVE-2026-33448LowApr 30, 2026
    risk 0.21cvss 3.3epss 0.00

    CVE-2026-33448 is a format string vulnerability in the logging subsystem of Secure Access client for MacOS prior to 14.50. Attackers with control of a modified server can force the client to dump the contents of a small portion of memory to the log files potentially revealing…

  • CVE-2025-54086LowOct 2, 2025
    risk 0.21cvss 3.3epss 0.00

    CVE-2025-54086 is an excess permissions vulnerability in the Warehouse component of Absolute Secure Access prior to version 14.10. Attackers with access to the local file system can read the Java keystore file. The attack complexity is low, there are no attack requirements, the…

  • CVE-2025-49082LowJul 31, 2025
    risk 0.18cvss 2.7epss 0.00

    CVE-2025-49082 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers with administrative access to the console and who have been assigned a certain set of permissions can bypass those permissions to improperly read other…

  • CVE-2025-54087LowOct 2, 2025
    risk 0.17cvss 2.6epss 0.00

    CVE-2025-54087 is a server-side request forgery vulnerability in Secure Access prior to version 14.10. Attackers with administrative privileges can publish a crafted test HTTP request originating from the Secure Access server. The attack complexity is high, there are no attack…

  • CVE-2026-55399MedJul 15, 2026
    risk 0.00cvss 4.3epss 0.00

    CVE-2026-55399 is a resource exhaustion vulnerability in the Secure Access publisher prior to 14.55. Attackers with valid credentials to the Secure Access tunnel can create a non-persistent DoS against the publisher.

  • CVE-2026-55398LowJul 15, 2026
    risk 0.00cvss 3.7epss 0.00

    CVE-2026-55398 is a memory management vulnerability in Secure Access clients and servers prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against the server.

  • CVE-2026-33445MedJul 15, 2026
    risk 0.00cvss 5.9epss 0.00

    CVE-2026-33445 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total control over the tunnel protocol can create a persistent DoS against the server.

  • CVE-2026-33444LowJul 15, 2026
    risk 0.00cvss 3.7epss 0.00

    CVE-2026-33444 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against the server.

  • CVE-2026-40958LowJul 15, 2026
    risk 0.00cvss 3.7epss 0.00

    CVE-2026-40958 is a input validation error in Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client.

  • CVE-2026-40957HigJul 15, 2026
    risk 0.00cvss 7.5epss 0.00

    o   CVE-2026-40957 is a frameable content vulnerability in the Secure Access server login page prior to 14.55. Attackers with control of a malicious web site could use it to potentially steal credentials from an unwary administrator.

  • CVE-2026-40956LowJul 15, 2026
    risk 0.00cvss 3.7epss 0.00

    CVE-2026-40956 is a memory disclosure vulnerability in Secure Access client versions prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can cause a small amount of random memory to leak.

  • CVE-2026-40955LowJul 15, 2026
    risk 0.00cvss 3.7epss 0.00

    CVE-2026-40955 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client.

  • CVE-2026-40954LowJul 15, 2026
    risk 0.00cvss 3.7epss 0.00

    CVE-2026-40954 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client

  • CVE-2026-40953MedJul 15, 2026
    risk 0.00cvss 4.4epss 0.00

    CVE-2026-40953 is a heap overflow in the certificate parsing function of Secure Access clients prior to 14.55. Attackers with local access and administrator permissions can create a denial of service attack against the client over which they have control.

  • CVE-2026-40952HigJul 15, 2026
    risk 0.00cvss 7.8epss 0.00

    CVE-2026-40952 is a privilege misconfiguration in the Secure Access installer for the Windows client and server prior to version 14.55. Attackers with local access to the client or server can use it to elevate privileges to Administrator when Secure Access is installed in a…

  • CVE-2026-33443MedJul 15, 2026
    risk 0.00cvss 5.9epss 0.00

    CVE-2026-33443 is a memory management error in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total control over the tunnel protocol can create a persistent DoS against the server.

Page 3 of 3