CVE-2026-55401
Received Received - Intake

Null Dereference in Secure Access Load Balancing Sub-System

Vulnerability report for CVE-2026-55401, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-13

Assigner: NetMotion Software

Description

CVE-2026-55401 is a null dereference vulnerability on the load-balancing sub-system of Secure Access servers prior to 14.57. Attackers can send an unauthenticated packet to a Secure Access server with load balancing enabled, which results in the internal load balancer crashing. After a successful attack, the Secure Access server is still able to accept connections and is still able to issue a failover to connected clients. ‍ https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-13
Generated
2026-08-13
AI Q&A
2026-08-13
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
netmotion_software secure_access to 14.57 (exc)
netmotionsoftware secure_access 14.57

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-55401 is a null dereference vulnerability in the load-balancing subsystem of Secure Access servers running versions prior to 14.57. An unauthenticated attacker can send a specially crafted packet to trigger a crash in the internal load balancer. The server remains operational and can still accept connections and perform failovers to clients.

Detection Guidance

This vulnerability can be detected by checking the version of Secure Access servers with load balancing enabled. If the version is prior to 14.57, the system is vulnerable. Monitor server logs for crashes in the load-balancing sub-system after receiving unauthenticated packets.

Impact Analysis

This vulnerability allows attackers to disrupt the load-balancing function of Secure Access servers, potentially causing service interruptions or degraded performance. While the server remains functional, the crash could lead to inconsistent traffic distribution and increased latency for connected clients.

Compliance Impact

The vulnerability causes temporary disruption in load balancing but does not directly compromise data confidentiality or integrity. It may impact availability of services, which could affect compliance with availability requirements in GDPR and HIPAA.

Mitigation Strategies

Update Secure Access servers to version 14.57 or later to address the null dereference vulnerability in the load-balancing sub-system.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-55401. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart