CVE-2026-40955: Integer underflow vulnerability in Secure Access clients
Published Jul 15, 2026
·Updated
CVE-2026-40955 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client.
Affected Software
2 affected components
Zscaler Secure Access client<14.55
Absolute Secure Access<14.55
Event History
Jul 15, 2026
CVE Published
via MITRE·07:50 PM
Data Sourced
via MITRE·07:50 PM
Description
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-40955?
CVE-2026-40955 has a risk score of 18, indicating a critical vulnerability.
2
How do I fix CVE-2026-40955?
To mitigate CVE-2026-40955, update the Zscaler Secure Access client to version 14.55 or later.
3
Who is affected by CVE-2026-40955?
CVE-2026-40955 affects users of Secured Access clients prior to version 14.55.
4
What type of attack is possible with CVE-2026-40955?
CVE-2026-40955 allows attackers to launch a non-persistent Denial of Service (DoS) attack.
5
What is the nature of the vulnerability in CVE-2026-40955?
CVE-2026-40955 is an integer underflow vulnerability located in the traffic parsing function.