SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-40956

LOW · CVSS 3.7 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-07-15 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

A memory disclosure vulnerability exists in Secure Access client versions prior to 14.55, allowing attackers with full control over the tunnel protocol to leak a small amount of random memory. While the severity is rated low, organizations using affected versions should prioritize patching to mitigate potential information exposure risks. This is particularly relevant for environments where sensitive data may be processed through the Secure Access client.

CVE
CVE-2026-40956
Severity
LOW
CVSS
3.7
EPSS
0.17%

Original NVD Description

CVE-2026-40956 is a memory disclosure vulnerability in Secure Access client versions prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can cause a small amount of random memory to leak.

Related CVEs

Other vulnerabilities affecting the same vendor(s)