SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-15506

HIGH · CVSS 7.8 EPSS 0.14% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-12 · Last synced 2026-08-11

CyberRota Analysis

AI-Generated

A heap-based buffer overflow vulnerability exists in the saappctl.sys library of SecureAge CatchPulse versions up to 10.9.3, which can be exploited locally. Successful exploitation may allow an attacker to manipulate memory, potentially leading to arbitrary code execution. Organizations using affected versions should prioritize upgrading to version 10.10.0 to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-15506
Severity
HIGH
CVSS
7.8
EPSS
0.14%

Original NVD Description

A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. The affected element is an unknown function in the library saappctl.sys of the component Driver. Such manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. Upgrading to version 10.10.0 is sufficient to fix this issue. You should upgrade the affected component. The vendor was contacted early about this disclosure.