Secure Access
Vendor:
First CVE: Jun 20, 2024 · Active for 2 years
52
Total CVEs
More Total CVEs than 98% of tracked products
17.3
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
5.2
Avg CVSS
Higher Avg CVSS than 9% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Secure Access over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 20, 2024
2 years ago
Most Recent CVE
Jul 15, 2026
9 days ago
CVE Severity & Scoring
Secure Access52 CVEs
40%
38%
15%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local10 (19.2%)
Network41 (78.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (1.9%)
Attack Complexity
Low42 (80.8%)
High10 (19.2%)
Unknown0 (0.0%)
User Interaction
None37 (71.2%)
Unknown0 (0.0%)
Required15 (28.8%)
Privileges Required
Low10 (19.2%)
High23 (44.2%)
None19 (36.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (52 CVEs).
52 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33447CRITICAL CVE-2026-33447 is a buffer overflow in a message parsing function of the
Secure Access client prior to 14.50. Attackers with control of a
modified server can send a special packe | Apr 30, 2026 | 9.8 | 37 | NO | NO |
CVE-2026-33446CRITICAL CVE-2026-33446 is a buffer overflow in the authentication sub-system of
the Secure Access client prior to 14.50. Attackers with control of a
modified server can send a special pa | Apr 30, 2026 | 9.8 | 36 | NO | NO |
CVE-2026-40957HIGH o
CVE-2026-40957 is a frameable content
vulnerability in the Secure Access server login page prior to 14.55. Attackers
with control of a malicious web site could use it to potent | Jul 15, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-40952HIGH CVE-2026-40952 is a privilege misconfiguration
in the Secure Access installer for the Windows client and server prior to
version 14.55. Attackers with local access to the client or | Jul 15, 2026 | 7.8 | 33 | NO | NO |
CVE-2026-33445MEDIUM CVE-2026-33445 is a memory management
vulnerability in Secure Access servers prior to 14.55. Attackers with an
intimate knowledge of and total control over the tunnel protocol can | Jul 15, 2026 | 5.9 | 31 | NO | NO |
CVE-2026-33451HIGH CVE-2026-33451 is an arbitrary read/write vulnerability in the Secure
Access Windows client prior to 14.50. Attackers with local control of
the Windows client can send malformed | Apr 30, 2026 | 7.8 | 31 | NO | NO |
CVE-2026-33443MEDIUM CVE-2026-33443 is a memory management error in
Secure Access servers prior to 14.55. Attackers with an intimate knowledge of
and total control over the tunnel protocol can create a | Jul 15, 2026 | 5.9 | 30 | NO | NO |
CVE-2026-33449HIGH CVE-2026-33449 is a buffer overflow in a message handling function of
the Secure Access client prior to 14.50. Attackers with control of
a modified server can send a cryptographi | Apr 30, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-40950MEDIUM CVE-2026-40950 is a buffer overflow vulnerability in the Secure Access
server prior to 14.50. Attackers with control of a modified client can
send a specially crafted message to | Apr 30, 2026 | 6.5 | 28 | NO | NO |
CVE-2025-49084CRITICAL CVE-2025-49084 is a vulnerability in the management console
of Absolute Secure Access prior to version 13.56. Attackers with administrative
access can overwrite policy rules withou | Jul 31, 2025 | 9.1 | 27 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (52 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (52 CVEs).
Media Mentions
Signals from CVEs in this product scope (52 CVEs).
Top CWEs
Versions
No cataloged versions.