Description
CVE-2026-33445 is a memory management
vulnerability in Secure Access servers prior to 14.55. Attackers with an
intimate knowledge of and total control over the tunnel protocol can create a
persistent DoS against the server.
Published: 2026-07-15
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

CVE-2026-33445 is a memory‑management defect that could allow an attacker to trigger a persistent denial of service by exhausting server memory. The flaw is triggered when specially crafted tunnel traffic is processed, causing allocation errors and eventual crash or hang. The weakness is classified as CWE‑400. The description indicates that a malicious actor who can control the tunnel traffic and has detailed protocol knowledge could create a persistent DoS; the characterization of the attacker as remote is inferred rather than directly stated.

Affected Systems

Absolute Security’s Secure Access server versions earlier than 14.55 are affected, regardless of sub‑version details. No other vendor or product has been identified as vulnerable.

Risk and Exploitability

The CVSS score of 8.7 signals high severity. The EPSS score is below 1 %, indicating a low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no documented widespread use. The analysis infers that effective exploitation requires deep protocol knowledge and control over the tunnel, limiting the attack surface to insiders or privileged network operators. Nonetheless, a successful attack would lead to service disruption and loss of availability.

Generated by OpenCVE AI on July 31, 2026 at 02:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Absolute Security Secure Access update 14.55 or newer
  • Enforce strict authentication and access controls on the tunnel protocol and implement traffic rate limiting
  • Configure system monitoring to detect abnormal memory consumption and restart the service automatically if thresholds are exceeded

Generated by OpenCVE AI on July 31, 2026 at 02:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Absolute
Absolute secure Access
Vendors & Products Absolute
Absolute secure Access

Thu, 16 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description CVE-2026-33445 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total control over the tunnel protocol can create a persistent DoS against the server.
Title Memory management vulnerability in Secure Access servers
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Absolute Secure Access
cve-icon MITRE

Status: PUBLISHED

Assigner: Absolute

Published:

Updated: 2026-07-16T13:09:35.944Z

Reserved: 2026-03-19T23:04:05.695Z

Link: CVE-2026-33445

cve-icon Vulnrichment

Updated: 2026-07-16T13:09:32.638Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T03:00:06Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption