← Vulnerability feed

Vulnerability record · CVE-2025-49080 · published 12 June 2025

CVE-2025-49080: Absolute secure access vulnerability

Absolute · Secure Access

There is a memory management vulnerability in Absolute Secure Access server versions 9.0 to 13.54. Attackers with network access to the server can cause a Denial of Service by sending a specially crafted sequence of packets to the server. The attack complexity is low, there are no attack requirements, privileges, or user interaction required. Loss of availability is high; there is no impact on confidentiality or integrity.

8.7 CVSS 4.0 High EPSS 0.37% · top 71.7% CWE-762 · CWE-762
8.7CVSS 4.0 base score
0.37%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

There is a memory management vulnerability in Absolute Secure Access server versions 9.0 to 13.54. Attackers with network access to the server can cause a Denial of Service by sending a specially crafted sequence of packets to the server. The attack complexity is low, there are no attack requirements, privileges, or user interaction required. Loss of availability is high; there is no impact on confidentiality or integrity.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-49080 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.7CVE-2026-55402Absolute secure access out-of-bounds read vulnerabilityCVE-2026-55402 is an out of bounds read vulnerability in Secure Access servers prior to version 14.57. Attackers with an ‘in the middle’ position can…EPSS 0.40%8.7CVE-2026-33445Absolute secure access uncontrolled resource consumption vulnerabilityCVE-2026-33445 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total contro…EPSS 0.40%8.5CVE-2026-40952Absolute secure access incorrect default permissions vulnerabilityCVE-2026-40952 is a privilege misconfiguration in the Secure Access installer for the Windows client and server prior to version 14.55. Attackers wit…EPSS 0.14%8.5CVE-2026-33451Absolute secure access out-of-bounds read vulnerabilityCVE-2026-33451 is an arbitrary read/write vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windo…EPSS 0.15%8.2CVE-2025-59595Absolute secure access improper input validation vulnerabilityCVE-2025-59595 is an internally discovered denial of service vulnerability in versions of Secure Access prior to 14.12. An attacker can send a specia…EPSS 0.34%7.1CVE-2026-33443Absolute secure access uncontrolled resource consumption vulnerabilityCVE-2026-33443 is a memory management error in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total control over t…EPSS 0.37%7.1CVE-2026-40950Absolute secure access stack-based buffer overflow vulnerabilityCVE-2026-40950 is a buffer overflow vulnerability in the Secure Access server prior to 14.50. Attackers with control of a modified client can send a …EPSS 0.42%7.0CVE-2025-49083Absolute secure access deserialization of untrusted data vulnerabilityCVE-2025-49083 is a vulnerability in the management console of Absolute Secure Access after version 12.00 and prior to version 13.56. Attackers with …EPSS 0.37%

Source: NIST National Vulnerability Database (record CVE-2025-49080), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.