← Vulnerability feed

Vulnerability record · CVE-2025-59595 · published 4 November 2025

CVE-2025-59595: Absolute secure access improper input validation vulnerability

Absolute · Secure Access

CVE-2025-59595 is an internally discovered denial of service vulnerability in versions of Secure Access prior to 14.12. An attacker can send a specially crafted packet to a server in a non-default configuration and cause the server to crash.

8.2 CVSS 4.0 High EPSS 0.34% · top 75.5% CWE-20 · Improper input validation
8.2CVSS 4.0 base score
0.34%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

CVE-2025-59595 is an internally discovered denial of service vulnerability in versions of Secure Access prior to 14.12. An attacker can send a specially crafted packet to a server in a non-default configuration and cause the server to crash.

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-59595 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.7CVE-2026-55402Absolute secure access out-of-bounds read vulnerabilityCVE-2026-55402 is an out of bounds read vulnerability in Secure Access servers prior to version 14.57. Attackers with an ‘in the middle’ position can…EPSS 0.40%8.7CVE-2026-33445Absolute secure access uncontrolled resource consumption vulnerabilityCVE-2026-33445 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total contro…EPSS 0.40%8.7CVE-2025-49080Absolute secure access vulnerabilityThere is a memory management vulnerability in Absolute Secure Access server versions 9.0 to 13.54. Attackers with network access to the server can ca…EPSS 0.37%8.5CVE-2026-40952Absolute secure access incorrect default permissions vulnerabilityCVE-2026-40952 is a privilege misconfiguration in the Secure Access installer for the Windows client and server prior to version 14.55. Attackers wit…EPSS 0.14%8.5CVE-2026-33451Absolute secure access out-of-bounds read vulnerabilityCVE-2026-33451 is an arbitrary read/write vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windo…EPSS 0.15%7.1CVE-2026-33443Absolute secure access uncontrolled resource consumption vulnerabilityCVE-2026-33443 is a memory management error in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total control over t…EPSS 0.37%7.1CVE-2026-40950Absolute secure access stack-based buffer overflow vulnerabilityCVE-2026-40950 is a buffer overflow vulnerability in the Secure Access server prior to 14.50. Attackers with control of a modified client can send a …EPSS 0.42%7.0CVE-2025-49083Absolute secure access deserialization of untrusted data vulnerabilityCVE-2025-49083 is a vulnerability in the management console of Absolute Secure Access after version 12.00 and prior to version 13.56. Attackers with …EPSS 0.37%

Source: NIST National Vulnerability Database (record CVE-2025-59595), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.