Description
CVE-2026-33444 is a memory management
vulnerability in Secure Access servers prior to 14.55. Attackers with intimate
knowledge of and total control over the tunnel protocol can create a
non-persistent DoS against the server.
Published: 2026-07-15
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A memory management flaw in Secure Access servers allows an attacker who has intimate knowledge of, and total control over, the tunnel protocol to cause a non‑persistent denial of service. The exploit triggers a resource exhaustion condition that drops normal traffic but does not permanently compromise the host. The vulnerability is identified by CWE‑119 and CWE‑400, indicating improper bounds checks leading to memory corruption and uncontrolled resource usage.

Affected Systems

Absolute Security’s Secure Access servers, versions before 14.55, are susceptible. The flaw is present in all builds of the product that have not applied the update to 14.55 or later, regardless of deployment environment.

Risk and Exploitability

The CVSS score of 6.9 reflects a medium‑to‑high severity impact, but the EPSS score of < 1% indicates that exploitation attempts are expected to be rare. Because the vulnerability requires control over the tunnel protocol, the attack vector is likely limited to insiders or compromised remote partners; it is not an arbitrary remote exploit. The vulnerability is not listed in the CISA KEV catalog, suggesting no known public exploits, yet its ability to continuously disrupt service warrants preemptive action.

Generated by OpenCVE AI on July 31, 2026 at 02:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Secure Access to version 14.55 or later as soon as possible. \n
  • Restrict or segment traffic that engages the tunnel protocol to trusted networks, and consider firewall rules or VPN segmentation to limit exposure. \n
  • Implement server‑side monitoring and rate‑limiting for tunnel sessions to detect and mitigate suspicious activity or repeated DoS attempts.

Generated by OpenCVE AI on July 31, 2026 at 02:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Absolute
Absolute secure Access
Vendors & Products Absolute
Absolute secure Access

Thu, 16 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-400
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description CVE-2026-33444 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against the server.
Title Memory management vulnerability in Secure Access servers
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Absolute Secure Access
cve-icon MITRE

Status: PUBLISHED

Assigner: Absolute

Published:

Updated: 2026-07-16T13:10:18.013Z

Reserved: 2026-03-19T23:04:05.695Z

Link: CVE-2026-33444

cve-icon Vulnrichment

Updated: 2026-07-16T13:10:13.804Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T03:00:06Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-400

    Uncontrolled Resource Consumption