← Vulnerability feed

Vulnerability record · CVE-2026-33445 · published 15 July 2026

CVE-2026-33445: Absolute secure access uncontrolled resource consumption vulnerability

Absolute · Secure Access

CVE-2026-33445 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total control over the tunnel protocol can create a persistent DoS against the server.

8.7 CVSS 4.0 High EPSS 0.40% · top 67.9% CWE-400 · Uncontrolled resource consumption
8.7CVSS 4.0 base score
0.40%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
16 Jul 2026Last modified by NVD

Description

CVE-2026-33445 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total control over the tunnel protocol can create a persistent DoS against the server.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-33445 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.7CVE-2026-55402Absolute secure access out-of-bounds read vulnerabilityCVE-2026-55402 is an out of bounds read vulnerability in Secure Access servers prior to version 14.57. Attackers with an ‘in the middle’ position can…EPSS 0.40%8.7CVE-2025-49080Absolute secure access vulnerabilityThere is a memory management vulnerability in Absolute Secure Access server versions 9.0 to 13.54. Attackers with network access to the server can ca…EPSS 0.37%8.5CVE-2026-40952Absolute secure access incorrect default permissions vulnerabilityCVE-2026-40952 is a privilege misconfiguration in the Secure Access installer for the Windows client and server prior to version 14.55. Attackers wit…EPSS 0.14%8.5CVE-2026-33451Absolute secure access out-of-bounds read vulnerabilityCVE-2026-33451 is an arbitrary read/write vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windo…EPSS 0.15%8.2CVE-2025-59595Absolute secure access improper input validation vulnerabilityCVE-2025-59595 is an internally discovered denial of service vulnerability in versions of Secure Access prior to 14.12. An attacker can send a specia…EPSS 0.34%7.1CVE-2026-33443Absolute secure access uncontrolled resource consumption vulnerabilityCVE-2026-33443 is a memory management error in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total control over t…EPSS 0.37%7.1CVE-2026-40950Absolute secure access stack-based buffer overflow vulnerabilityCVE-2026-40950 is a buffer overflow vulnerability in the Secure Access server prior to 14.50. Attackers with control of a modified client can send a …EPSS 0.42%7.0CVE-2025-49083Absolute secure access deserialization of untrusted data vulnerabilityCVE-2025-49083 is a vulnerability in the management console of Absolute Secure Access after version 12.00 and prior to version 13.56. Attackers with …EPSS 0.37%

Source: NIST National Vulnerability Database (record CVE-2026-33445), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.