Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Absolute Software

First CVE: May 11, 2018Active for: 8 yearsTotal CVEs: 57
19.1
VTI Score
Low

Absolute Software develops endpoint management, security, and persistent access products deployed across enterprise fleets, a modest portfolio that is more prominent in the vulnerability landscape than typical for its size. Vulnerabilities affecting the vendor concentrate in its flagship products such as Secure Access, ComputTrace Agent, and its persistence and Windows agent offerings, with a meaningful share reaching serious severity. The recurring weakness classes—chiefly cross-site scripting, stack-based buffer overflows, improper access control, and input-validation flaws—reflect both the web-facing and system-level attack surfaces inherent to agent-based endpoint management and remote-access tools. Defenders should prioritize inventory of affected endpoint agents and treat agent-management interfaces as high-value targets. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
57
Total CVEs
More Total CVEs than 99% of tracked vendors
3.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
5.3
Avg CVSS Score
Higher Avg CVSS Score than 15% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Absolute Software over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 11, 2018
8 years ago
Most Recent CVE
Jul 15, 2026
9 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (57 CVEs).

57 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-33447CRITICAL
CVE-2026-33447 is a buffer overflow in a message parsing function of the Secure Access client prior to 14.50. Attackers with control of a modified server can send a special packe
Apr 30, 20269.837NONO
CVE-2026-33446CRITICAL
CVE-2026-33446 is a buffer overflow in the authentication sub-system of the Secure Access client prior to 14.50. Attackers with control of a modified server can send a special pa
Apr 30, 20269.836NONO
CVE-2026-40957HIGH
o   CVE-2026-40957 is a frameable content vulnerability in the Secure Access server login page prior to 14.55. Attackers with control of a malicious web site could use it to potent
Jul 15, 20267.533NONO
CVE-2026-40952HIGH
CVE-2026-40952 is a privilege misconfiguration in the Secure Access installer for the Windows client and server prior to version 14.55. Attackers with local access to the client or
Jul 15, 20267.833NONO
CVE-2026-33445MEDIUM
CVE-2026-33445 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total control over the tunnel protocol can
Jul 15, 20265.931NONO
CVE-2026-33451HIGH
CVE-2026-33451 is an arbitrary read/write vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can send malformed
Apr 30, 20267.831NONO
CVE-2026-33443MEDIUM
CVE-2026-33443 is a memory management error in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total control over the tunnel protocol can create a
Jul 15, 20265.930NONO
CVE-2026-33449HIGH
CVE-2026-33449 is a buffer overflow in a message handling function of the Secure Access client prior to 14.50. Attackers with control of a modified server can send a cryptographi
Apr 30, 20267.530NONO
CVE-2026-40950MEDIUM
CVE-2026-40950 is a buffer overflow vulnerability in the Secure Access server prior to 14.50. Attackers with control of a modified client can send a specially crafted message to
Apr 30, 20266.528NONO
CVE-2025-49084CRITICAL
CVE-2025-49084 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers with administrative access can overwrite policy rules withou
Jul 31, 20259.127NONO
View all 57 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products57 CVEs
37%
42%
16%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local13 (22.8%)
Network42 (73.7%)
Unknown0 (0.0%)
Physical1 (1.8%)
Adjacent Network1 (1.8%)
Attack Complexity
Low45 (78.9%)
High12 (21.1%)
Unknown0 (0.0%)
User Interaction
None42 (73.7%)
Unknown0 (0.0%)
Required15 (26.3%)
Privileges Required
Low11 (19.3%)
High26 (45.6%)
None20 (35.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (57 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Absolute Software.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Absolute Software — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Absolute Software's Products

View all 1 CNAs →

Top CWEs