Description
CVE-2026-97716
is a vulnerability in the connection set up sub-system of Secure Access servers
prior to version 14.60. Unauthenticated attackers can send specially crafted
traffic to the server and cause a persistent denial of service.
Published: 2026-10-07
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

A flaw in the connection set‑up subsystem of Secure Access allows an unauthenticated attacker to send specially crafted traffic that forces the server to fall into a state of persistent unresponsiveness. The result is a denial of service that can halt legitimate users from accessing the service. This vulnerability is a classic example of a remote DoS that does not require authentication to exploit, and the effect is a loss of availability on the affected servers.

Affected Systems

The vulnerability affects Absolute Security’s Secure Access product versions earlier than 14.60. Users running any pre‑14.60 build of Secure Access are exposed.

Risk and Exploitability

The CVSS score of 8.7 highlights the high impact of this deficiency, while the EPSS score is currently unavailable, indicating no measured probability at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote, unauthenticated traffic that targets the server’s connection initialization path. An attacker can exploit this weakness simply by sending malformed packets over the network; no credentials or local access are required, making the risk high for exposed installations.

Generated by OpenCVE AI on October 7, 2026 at 23:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Secure Access to version 14.60 or later to eliminate the flaw
  • If a patch is not immediately available, reconfigure the firewall or access controls to restrict inbound connections to the Secure Access service only to trusted hosts
  • Deploy application‑level health monitoring to detect and remediate server lock‑ups promptly

Generated by OpenCVE AI on October 7, 2026 at 23:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
Description CVE-2026-97716 is a vulnerability in the connection set up sub-system of Secure Access servers prior to version 14.60. Unauthenticated attackers can send specially crafted traffic to the server and cause a persistent denial of service.
Title Denial of Service in Absolute Secure Access
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Absolute

Published:

Updated: 2026-10-07T20:34:10.752Z

Reserved: 2026-09-24T22:30:33.466Z

Link: CVE-2026-97716

cve-icon Vulnrichment

Updated: 2026-10-07T20:34:06.082Z

cve-icon NVD

Status : Received

Published: 2026-10-07T20:17:16.193

Modified: 2026-10-07T21:17:23.267

Link: CVE-2026-97716

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T23:15:08Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption