SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-40954

LOW · CVSS 3.7 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-07-15 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

An integer underflow vulnerability exists in the traffic parsing function of Secure Access clients prior to version 14.55, allowing attackers with full control over the tunnel protocol to launch a non-persistent denial-of-service (DoS) attack against affected clients. While the severity is rated low, organizations using these clients should prioritize patching to mitigate potential disruptions in service. This is particularly relevant for environments where secure tunnel protocols are critical for operations.

CVE
CVE-2026-40954
Severity
LOW
CVSS
3.7
EPSS
0.20%

Original NVD Description

CVE-2026-40954 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client

Related CVEs

Other vulnerabilities affecting the same vendor(s)