Junglewise Threat Intelligence

CVE-2026-40954: Absolute Security Secure Access integer underflow in traffic parsing

CVE-2026-40954 · Severity: info · CVSS 2.1 · Published 2026-07-15

Technologies: Absolute Security Secure Access. Vendors: Absolute Security.

Executive brief

Absolute Security Secure Access (formerly NetMotion) is a VPN-like solution used to provide secure remote connectivity for mobile workforces. A vulnerability in how the client software processes network traffic could allow a highly sophisticated attacker to crash the application. This would result in a temporary loss of connectivity for the user, though it does not appear to allow for data theft or permanent system damage.

Technical details

An integer underflow vulnerability exists in the traffic parsing function of Absolute Security Secure Access clients prior to version 14.55. The flaw is triggered when the client processes specifically crafted tunnel protocol traffic. Exploitation requires the attacker to have intimate knowledge of and total control over the tunnel protocol, as well as user interaction. A successful exploit results in a non-persistent denial of service (DoS) against the affected client. The issue is addressed in client version 14.55.

Affected products

  • Absolute Security (NetMotion) Secure Access prior to 14.55

Timeline

  • 2026-07-15: advisory
  • 2026-07-15: disclosed

References

Related threats