CVE-2026-15506

HIGH

SecureAge CatchPulse Driver saappctl.sys heap-based overflow

Title source: cna
STIX 2.1

Description

A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. The affected element is an unknown function in the library saappctl.sys of the component Driver. Such manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. Upgrading to version 10.10.0 is sufficient to fix this issue. You should upgrade the affected component. The vendor was contacted early about this disclosure.

References (8)

Core 8
Core References
Signature, Permissions Required signature permissions-required
VDB-377835 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/377835/cti
Third Party Advisory third-party-advisory
CVE-2026-15506 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-15506
Vdb Entry vdb-entry technical-description
VDB-377835 | SecureAge CatchPulse Driver saappctl.sys heap-based overflow
https://vuldb.com/vuln/377835
Exploit media-coverage
https://youtu.be/xZqRVWlrah8
Third Party Advisory third-party-advisory
Submit #845584 | SecureAge Technology CatchPulse <10.9.3 Heap-based Buffer Overflow
https://vuldb.com/submit/845584

Scores

CVSS v3 7.8
EPSS 0.0014
EPSS Percentile 3.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-119 CWE-122
Status published
Products (5)
SecureAge/CatchPulse 10.10.0
SecureAge/CatchPulse 10.9.0
SecureAge/CatchPulse 10.9.1
SecureAge/CatchPulse 10.9.2
SecureAge/CatchPulse 10.9.3
Published Jul 12, 2026
Tracked Since Jul 13, 2026