CVE-2026-55401
Received
Received - Intake
Null Dereference in Secure Access Load Balancing Sub-System
Vulnerability report for CVE-2026-55401, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-13
Last updated on: 2026-08-13
Assigner: NetMotion Software
Description
Description
CVE-2026-55401 is a null dereference vulnerability on the load-balancing
sub-system of Secure Access servers prior to 14.57. Attackers can send
an unauthenticated packet to a Secure Access server with load balancing
enabled, which results in the internal load balancer crashing. After a
successful attack, the Secure Access server is still able to accept
connections and is still able to issue a failover to connected clients. β https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| netmotion_software | secure_access | to 14.57 (exc) |
| netmotionsoftware | secure_access | 14.57 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |