CVE-2026-40958: Input validation error in Secure Access clients prior to 14.55
Published Jul 15, 2026
·Updated
CVE-2026-40958 is a input validation error in Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client.
Affected Software
2 affected components
Ivanti Secure Access<14.55
Absolute Secure Access<14.55
Event History
Jul 15, 2026
CVE Published
via MITRE·08:02 PM
Data Sourced
via MITRE·08:02 PM
Description
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-40958?
CVE-2026-40958 has a risk score of 15, indicating a critical vulnerability.
2
How do I fix CVE-2026-40958?
To fix CVE-2026-40958, update your Ivanti Secure Access clients to version 14.55 or later.
3
What type of vulnerability is CVE-2026-40958?
CVE-2026-40958 is an input validation error in the Secure Access clients.
4
What impact does CVE-2026-40958 have?
CVE-2026-40958 can allow attackers to create a non-persistent denial of service against the client.
5
Which software is affected by CVE-2026-40958?
CVE-2026-40958 affects Ivanti Secure Access clients prior to version 14.55.