CVE-2026-40957: Frameable content vulnerability in the Secure Access server login page
Published Jul 15, 2026
·Updated
o CVE-2026-40957 is a frameable content vulnerability in the Secure Access server login page prior to 14.55. Attackers with control of a malicious web site could use it to potentially steal credentials from an unwary administrator.
Affected Software
2 affected components
Secure Access server login page<14.55
Absolute Secure Access<14.55
Event History
Jul 15, 2026
CVE Published
via MITRE·07:59 PM
Data Sourced
via MITRE·07:59 PM
Description
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-40957?
CVE-2026-40957 has a risk rating of 52, indicating a moderate level of severity.
2
How do I fix CVE-2026-40957?
To mitigate CVE-2026-40957, upgrade the Secure Access server login page to version 14.55 or later.
3
What type of vulnerability is CVE-2026-40957?
CVE-2026-40957 is classified as a frameable content vulnerability in the Secure Access server login page.
4
Who is affected by CVE-2026-40957?
Administrators using versions of the Secure Access server login page prior to 14.55 are at risk of CVE-2026-40957.
5
What can attackers achieve with CVE-2026-40957?
Attackers can potentially steal credentials from administrators by exploiting CVE-2026-40957.