AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-55401

MEDIUM · CVSS 6.9 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

A null dereference vulnerability exists in the load-balancing subsystem of Secure Access servers prior to version 14.57, allowing attackers to send unauthenticated packets that can crash the internal load balancer. Although the Secure Access server can still accept connections and perform failover for connected clients, this vulnerability may lead to service disruptions. Organizations using affected versions should prioritize patching to mitigate potential impacts on service availability.

CVE
CVE-2026-55401
Severity
MEDIUM
CVSS
6.9
EPSS
0.31%

Original NVD Description

CVE-2026-55401 is a null dereference vulnerability on the load-balancing sub-system of Secure Access servers prior to 14.57. Attackers can send an unauthenticated packet to a Secure Access server with load balancing enabled, which results in the internal load balancer crashing. After a successful attack, the Secure Access server is still able to accept connections and is still able to issue a failover to connected clients. ‍ https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L