CVE-2026-97716: high-severity vulnerability in Absolute Security Secure Access
Denial of Service in Absolute Secure Access
Published
18Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.7
exploitation probability
—
observed exploitation
nono source reports it
CVE-2026-97716
is a vulnerability in the connection set up sub-system of Secure Access servers
prior to version 14.60. Unauthenticated attackers can send specially crafted
traffic to the server and cause a persistent denial of service.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Affected products
Absolute Security · Secure AccessRelated CVEs — Absolute Security Secure Access
In the same product, most dangerous first.
CVE-2025-49081MEDIUMInput validation vulnerability in the Secure Access prior to version 13.55EPSS 0.5%CVE-2026-40957MEDIUMFrameable content vulnerability in the Secure Access server login pageEPSS 0.4%CVE-2026-55402HIGHCVE-2026-55402EPSS 0.4%CVE-2026-33445HIGHMemory management vulnerability in Secure Access serversEPSS 0.4%CVE-2026-55401MEDIUMCVE-2026-55401EPSS 0.4%CVE-2026-40958LOWInput validation error in Secure Access clients prior to 14.55EPSS 0.4%