CVE-2026-55402 is an out of bounds read vulnerability in Secure Access servers prior to version 14.57. Attackers with an ‘in the middle’ position can send specially crafted data to a server causing a persistent denial of service. This vulnerability has significant implications for organizations using affected Secure Access servers, as it could allow attackers to disrupt service. The CVE record was publish [truncated]
CVE-2026-55401 is a null dereference vulnerability in the load-balancing sub-system of Secure Access servers prior to version 14.57. An attacker can send an unauthenticated packet to a Secure Access server with load balancing enabled, causing the internal load balancer to crash. The Secure Access server remains operational, able to accept connections and issue a failover to connected clients. This vulnera [truncated]
CVE-2026-40957 is a frameable content vulnerability in the Secure Access server login page prior to 14.55. Attackers with control of a malicious web site could use it to potentially steal credentials from an unwary administrator. This vulnerability has a CVSS score of 6.1 and is classified as MEDIUM severity. The vulnerability allows attackers to potentially steal credentials from administrators who are t [truncated]
CVE-2026-40955 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. This vulnerability allows attackers with intimate knowledge of and total control over the tunnel protocol to create a non-persistent Denial of Service (DoS) against their client. The vulnerability has a CVSS score of 2.1, indicating a low severity. Users of Secure Access clients pr [truncated]