CVE-2026-40956

LOW

Memory disclosure in Secure Access Clients

Title source: cna
STIX 2.1

Description

CVE-2026-40956 is a memory disclosure vulnerability in Secure Access client versions prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can cause a small amount of random memory to leak.

Scores

CVSS v3 3.7
EPSS 0.0017
EPSS Percentile 6.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (2)
absolute/secure_access < 14.55
Absolute Security/Secure Access < 14.55
Published Jul 15, 2026
Tracked Since Jul 16, 2026