Description
CVE-2026-33443 is a memory management error in
Secure Access servers prior to 14.55. Attackers with an intimate knowledge of
and total control over the tunnel protocol can create a persistent DoS against
the server.
Published: 2026-07-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A memory management error exists in Secure Access servers prior to version 14.55. This flaw allows an attacker with intimate knowledge of and full control over the tunnel protocol to trigger a persistent denial of service, making the server unavailable to legitimate users. The root cause is uncontrolled resource consumption, classified as CWE-400.

Affected Systems

Absolute Security’s Secure Access servers running any version before 14.55 are vulnerable. These servers are exposed to the tunnel protocol that the attacker must manipulate to exhaust resources.

Risk and Exploitability

The flaw carries a CVSS score of 7.1, indicating high severity, but the EPSS score is under 1%, signifying a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Because exploitation requires deep understanding of the proprietary tunnel protocol and full authority over the connection, the attack vector is likely restricted to trusted or compromised clients and is not easily achievable by a generic attacker.

Generated by OpenCVE AI on July 31, 2026 at 02:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Secure Access to version 14.55 or later to eliminate the memory‑management flaw.
  • Restrict tunnel access to known, authenticated clients and reject malformed traffic to reduce the opportunity for resource exhaustion.
  • Monitor for abnormal CPU or memory usage during tunnel sessions and apply rate limiting or temporary blocking of offending connections as a short‑term mitigation.

Generated by OpenCVE AI on July 31, 2026 at 02:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Absolute
Absolute secure Access
Vendors & Products Absolute
Absolute secure Access

Thu, 16 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Description CVE-2026-33443 is a memory management error in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total control over the tunnel protocol can create a persistent DoS against the server.
Title Memory management error in Secure Access servers prior to 14.55
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Absolute Secure Access
cve-icon MITRE

Status: PUBLISHED

Assigner: Absolute

Published:

Updated: 2026-07-16T13:11:10.328Z

Reserved: 2026-03-19T23:04:05.695Z

Link: CVE-2026-33443

cve-icon Vulnrichment

Updated: 2026-07-16T13:11:06.733Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T03:00:06Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption