Junglewise Threat Intelligence

CVE-2026-55398: Absolute Security Secure Access memory management denial of service

CVE-2026-55398 · Severity: info · CVSS 6.9 · Published 2026-07-15

Technologies: Absolute Security Secure Access. Vendors: Absolute Security.

Executive brief

Absolute Security Secure Access, a solution used to provide secure remote connectivity for mobile workforces, is affected by a memory management flaw. An attacker with deep technical knowledge of the communication protocol could exploit this to temporarily crash the server. This would result in a denial-of-service, preventing legitimate users from connecting to corporate resources until the service is restored.

Technical details

A memory management vulnerability exists in Absolute Security (formerly NetMotion) Secure Access clients and servers prior to version 14.55. The flaw is located within the handling of the tunnel protocol. A remote attacker with intimate knowledge of and control over the tunnel protocol can trigger the vulnerability to cause a non-persistent denial-of-service (DoS) against the server. The vendor has assigned a CVSS 4.0 score of 6.9, noting that while the attack vector is network-based, it requires specific protocol manipulation. The issue is resolved in version 14.55.

Affected products

  • Absolute Security (NetMotion) Secure Access prior to 14.55

Timeline

  • 2026-07-15: advisory
  • 2026-07-15: disclosed

References

Related threats