Junglewise Threat Intelligence

CVE-2026-33444: Absolute Security Secure Access memory management DoS

CVE-2026-33444 · Severity: info · CVSS 6.9 · Published 2026-07-15

Technologies: Absolute Security Secure Access. Vendors: Absolute Security.

Executive brief

Absolute Security Secure Access (formerly NetMotion) is a remote access solution used to provide secure connectivity for mobile workforces. A memory management flaw allows an attacker to disrupt the service, causing a temporary denial-of-service. While this does not expose customer data, it can prevent employees from accessing critical corporate resources until the service is restored.

Technical details

A memory management vulnerability exists in Absolute Security (formerly NetMotion) Secure Access servers prior to version 14.55. The flaw is triggered by an attacker with total control over the tunnel protocol, allowing them to induce a non-persistent denial-of-service (DoS) condition. The attack vector is network-based and does not require authentication, though it requires specific knowledge of the proprietary tunnel protocol. The issue is resolved in version 14.55 and later.

Affected products

  • Absolute Security (NetMotion) Secure Access prior to 14.55

Timeline

  • 2026-07-15: disclosed
  • 2026-07-15: advisory

References

Related threats