CVE-2026-40955
Last modified
CVE-2026-40955 is a low-severity vulnerability rated 3.7/10 on the CVSS scale. CVE-2026-40955 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client.. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
CVE-2026-40955 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Absolute | Secure Access | < 14.55 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2026-40955?
How severe is CVE-2026-40955?
How do I fix CVE-2026-40955?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-40949CVE-2026-40949 is a buffer overflow vulnerability in the Sec…4.4
- CVE-2026-40950CVE-2026-40950 is a buffer overflow vulnerability in the Sec…6.5
- CVE-2026-40951CVE-2026-40951 is a memory corruption vulnerability on Secur…5.5
- CVE-2026-40952CVE-2026-40952 is a privilege misconfiguration in the Secure…7.8
- CVE-2026-40953CVE-2026-40953 is a heap overflow in the certificate parsing…4.4
- CVE-2026-40954CVE-2026-40954 is an integer underflow vulnerability in the …3.7
- CVE-2026-40956CVE-2026-40956 is a memory disclosure vulnerability in Secur…3.7
- CVE-2026-40957o CVE-2026-40957 is a frameable content vulnerability in t…7.5
- CVE-2026-40958CVE-2026-40958 is a input validation error in Secure Access …3.7
- CVE-2026-40959Luanti 5 before 5.15.2, when LuaJIT is used, allows a Lua sa…9.3
- CVE-2026-4096IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP he…6.1
- CVE-2026-40960Luanti 5 before 5.15.2 sometimes allows unintended access to…8.1
Are you affected by CVE-2026-40955?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
