Junglewise Threat Intelligence

CVE-2026-40955: Absolute Security Secure Access integer underflow in traffic parsing

CVE-2026-40955 · Severity: info · CVSS 2.1 · Published 2026-07-15

Technologies: Absolute Security Secure Access. Vendors: Absolute Security.

Executive brief

A vulnerability in the Absolute Secure Access client could allow a highly sophisticated attacker to temporarily disrupt the software's connection. To exploit this, an attacker would need total control over the network tunnel protocol and specific technical knowledge of the system's internals. The impact is limited to a non-persistent denial of service, meaning the application may crash or hang but can be restarted.

Technical details

An integer underflow vulnerability exists within the traffic parsing function of Absolute Security (formerly NetMotion) Secure Access clients. The flaw is triggered when the client processes specifically crafted tunnel protocol traffic. Exploitation requires the attacker to have intimate knowledge of and total control over the tunnel protocol, as well as user interaction. Successful exploitation results in a non-persistent denial of service (DoS) of the client application. The issue is addressed in Secure Access client version 14.55.

Affected products

  • Absolute Security (NetMotion) Secure Access prior to 14.55

Timeline

  • 2026-07-15: disclosed
  • 2026-07-15: advisory

References

Related threats