CVE-2026-55402 is an out of bounds read vulnerability in Secure Access
servers prior to version 14.57. Attackers with an ‘in the middle’
position can send specially crafted data to a server causing a
persistent denial of service.
CVE-2026-55400 is an integer underflow in Secure Access servers prior to
version 14.57. Attackers with an authenticated session can send
specially crafted traffic to a server in a non-default configuration and
cause a persistent denial of service.
CVE-2026-55401 is a null dereference vulnerability on the load-balancing
sub-system of Secure Access servers prior to 14.57. Attackers can send
an unauthenticated packet to a Secure Access server with load balancing
enabled, which results in the internal load balancer crashing. After a
successful attack, the Secure Access server is still able to accept
connections and is still able to issue a failover to connected clients. https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L
CVE-2026-55399 is a resource exhaustion
vulnerability in the Secure Access publisher prior to 14.55. Attackers with
valid credentials to the Secure Access tunnel can create a non-persistent DoS
against the publisher.
CVE-2026-55398
is a memory management vulnerability in Secure Access clients and servers prior
to 14.55. Attackers with intimate knowledge of and total control over the
tunnel protocol can create a non-persistent DoS against the server.
CVE-2026-33444 is a memory management
vulnerability in Secure Access servers prior to 14.55. Attackers with intimate
knowledge of and total control over the tunnel protocol can create a
non-persistent DoS against the server.
CVE-2026-33445 is a memory management
vulnerability in Secure Access servers prior to 14.55. Attackers with an
intimate knowledge of and total control over the tunnel protocol can create a
persistent DoS against the server.
CVE-2026-40956
is a memory disclosure vulnerability in Secure Access client versions prior to 14.55.
Attackers with intimate knowledge of and total control over the tunnel protocol
can cause a small amount of random memory to leak.
o
CVE-2026-40957 is a frameable content
vulnerability in the Secure Access server login page prior to 14.55. Attackers
with control of a malicious web site could use it to potentially steal
credentials from an unwary administrator.
CVE-2026-40958
is a input validation error in Secure Access clients prior to 14.55. Attackers
with intimate knowledge of and total control over the tunnel protocol can
create a non-persistent DoS against their client.