CVE-2026-40958
Modified Modified - Updated After Analysis

Input Validation Flaw in Secure Access Client Leads to DoS

Vulnerability report for CVE-2026-40958, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-15

Last updated on: 2026-07-16

Assigner: NetMotion Software

Description

CVE-2026-40958 is a input validation error in Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-15
Last Modified
2026-07-16
Generated
2026-08-05
AI Q&A
2026-07-16
EPSS Evaluated
2026-08-03
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
absolute secure_access to 14.55 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-40958 is an input validation error in Secure Access clients before version 14.55. Attackers with full knowledge and control over the tunnel protocol can cause a temporary disruption in the client's operation through a non-persistent denial-of-service (DoS) attack.

Detection Guidance

Detection of CVE-2026-40958 requires monitoring for unusual client behavior or tunnel protocol anomalies. Check Secure Access client logs for repeated disconnections or protocol errors. Use network monitoring tools to detect non-persistent DoS patterns targeting the client.

Impact Analysis

This vulnerability could temporarily disrupt the operation of Secure Access clients if an attacker exploits it. The impact is limited to non-persistent DoS, meaning normal functionality returns after the attack stops.

Compliance Impact

This vulnerability does not directly impact compliance with standards like GDPR or HIPAA as it only causes temporary disruption to the client without data exposure or persistent damage.

Mitigation Strategies

Immediately update Secure Access clients to version 14.55 or later to patch the input validation flaw. Ensure all clients are running the latest version to prevent exploitation. Monitor for any signs of DoS activity during the transition.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-40958. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart