CVE-2026-40956: Memory disclosure in Secure Access Clients
CVE-2026-40956 is a memory disclosure vulnerability in Secure Access client versions prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can cause a small amount of random memory to leak.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Secure Access clientto a version that resolves this vulnerability.Fixed in 14.55Patch CVE-2026-40956
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40956?
CVE-2026-40956 has a severity rating of 10, indicating critical risk.
How do I fix CVE-2026-40956?
To remediate CVE-2026-40956, upgrade to the Secure Access client version 14.55 or later.
What type of vulnerability is CVE-2026-40956?
CVE-2026-40956 is a memory disclosure vulnerability affecting Secure Access clients.
Who is affected by CVE-2026-40956?
CVE-2026-40956 affects users of Secure Access client versions prior to 14.55.
Can CVE-2026-40956 be exploited remotely?
Yes, CVE-2026-40956 can be exploited by attackers who have full control over the tunnel protocol.