Junglewise Threat Intelligence

CVE-2026-33445: Absolute Security Secure Access memory management DoS in server

CVE-2026-33445 · Severity: info · CVSS 8.7 · Published 2026-07-15

Technologies: Absolute Security Secure Access. Vendors: Absolute Security.

Executive brief

Absolute Security Secure Access servers (formerly NetMotion) are affected by a memory management flaw that can lead to a service outage. An attacker with specialized knowledge of the system's communication protocol can crash the server, preventing legitimate users from securely accessing corporate resources. This results in a persistent denial-of-service condition that disrupts remote work operations.

Technical details

A memory management vulnerability exists in the server component of Absolute Security Secure Access (formerly NetMotion) prior to version 14.55. The flaw is triggered by specific manipulations of the tunnel protocol. An attacker with intimate knowledge of and total control over the tunnel protocol can exploit this vulnerability to cause a persistent denial-of-service (DoS) against the server. The attack is network-reachable and requires no prior authentication or user interaction. The vendor has addressed this issue in version 14.55.

Affected products

  • Absolute Security (NetMotion Software) Secure Access prior to 14.55

Timeline

  • 2026-07-15: disclosed
  • 2026-07-15: advisory

References

Related threats