Absolute Software develops endpoint management, security, and persistent access products deployed across enterprise fleets, a modest portfolio that is more prominent in the vulnerability landscape than typical for its size. Vulnerabilities affecting the vendor concentrate in its flagship products such as Secure Access, ComputTrace Agent, and its persistence and Windows agent offerings, with a meaningful share reaching serious severity. The recurring weakness classes—chiefly cross-site scripting, stack-based buffer overflows, improper access control, and input-validation flaws—reflect both the web-facing and system-level attack surfaces inherent to agent-based endpoint management and remote-access tools. Defenders should prioritize inventory of affected endpoint agents and treat agent-management interfaces as high-value targets. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Absolute Software over time
Signals from CVEs in this vendor scope (57 CVEs).
57 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33447CRITICAL CVE-2026-33447 is a buffer overflow in a message parsing function of the
Secure Access client prior to 14.50. Attackers with control of a
modified server can send a special packe | Apr 30, 2026 | 9.8 | 37 | NO | NO |
CVE-2026-33446CRITICAL CVE-2026-33446 is a buffer overflow in the authentication sub-system of
the Secure Access client prior to 14.50. Attackers with control of a
modified server can send a special pa | Apr 30, 2026 | 9.8 | 36 | NO | NO |
CVE-2026-40957HIGH o
CVE-2026-40957 is a frameable content
vulnerability in the Secure Access server login page prior to 14.55. Attackers
with control of a malicious web site could use it to potent | Jul 15, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-40952HIGH CVE-2026-40952 is a privilege misconfiguration
in the Secure Access installer for the Windows client and server prior to
version 14.55. Attackers with local access to the client or | Jul 15, 2026 | 7.8 | 33 | NO | NO |
CVE-2026-33445MEDIUM CVE-2026-33445 is a memory management
vulnerability in Secure Access servers prior to 14.55. Attackers with an
intimate knowledge of and total control over the tunnel protocol can | Jul 15, 2026 | 5.9 | 31 | NO | NO |
CVE-2026-33451HIGH CVE-2026-33451 is an arbitrary read/write vulnerability in the Secure
Access Windows client prior to 14.50. Attackers with local control of
the Windows client can send malformed | Apr 30, 2026 | 7.8 | 31 | NO | NO |
CVE-2026-33443MEDIUM CVE-2026-33443 is a memory management error in
Secure Access servers prior to 14.55. Attackers with an intimate knowledge of
and total control over the tunnel protocol can create a | Jul 15, 2026 | 5.9 | 30 | NO | NO |
CVE-2026-33449HIGH CVE-2026-33449 is a buffer overflow in a message handling function of
the Secure Access client prior to 14.50. Attackers with control of
a modified server can send a cryptographi | Apr 30, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-40950MEDIUM CVE-2026-40950 is a buffer overflow vulnerability in the Secure Access
server prior to 14.50. Attackers with control of a modified client can
send a specially crafted message to | Apr 30, 2026 | 6.5 | 28 | NO | NO |
CVE-2025-49084CRITICAL CVE-2025-49084 is a vulnerability in the management console
of Absolute Secure Access prior to version 13.56. Attackers with administrative
access can overwrite policy rules withou | Jul 31, 2025 | 9.1 | 27 | NO | NO |
Signals from CVEs in this vendor scope (57 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Absolute Software.
Media articles that mention a CVE ID that affects a product developed by Absolute Software — matched by CVE ID, not by vendor name.