CVE-2026-40954: Integer underflow in Secure Access clients prior to 14.55
Published Jul 15, 2026
·Updated
CVE-2026-40954 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client
Affected Software
2 affected components
Secure Access clients<14.55
Absolute Secure Access<14.55
Event History
Jul 15, 2026
CVE Published
via MITRE·07:44 PM
Data Sourced
via MITRE·07:44 PM
Description
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-40954?
CVE-2026-40954 has a severity rating of 15.
2
What type of vulnerability is CVE-2026-40954?
CVE-2026-40954 is an integer underflow vulnerability.
3
How do I fix CVE-2026-40954?
To fix CVE-2026-40954, update your Secure Access clients to version 14.55 or later.
4
What impact does CVE-2026-40954 have on my system?
CVE-2026-40954 allows attackers to perform a non-persistent Denial of Service (DoS) against vulnerable client software.
5
Who is affected by CVE-2026-40954?
CVE-2026-40954 affects users of Secure Access clients prior to version 14.55.