CVE-2026-33450
- EPSS 0.16%
- Veröffentlicht 30.04.2026 20:04:14
- Zuletzt bearbeitet 05.05.2026 02:31:13
CVE-2026-33450 is an out of bounds read vulnerability in the Secure Access MacOS client prior to 14.50. Attackers with control of a modified server can send a malformed packet to the client causing a denial of service.
CVE-2026-33449
- EPSS 0.24%
- Veröffentlicht 30.04.2026 19:52:01
- Zuletzt bearbeitet 05.05.2026 02:27:54
CVE-2026-33449 is a buffer overflow in a message handling function of the Secure Access client prior to 14.50. Attackers with control of a modified server can send a cryptographically valid message to the client, overwriting a small portion of mem...
CVE-2026-33448
- EPSS 0.1%
- Veröffentlicht 30.04.2026 19:47:50
- Zuletzt bearbeitet 05.05.2026 02:27:26
CVE-2026-33448 is a format string vulnerability in the logging subsystem of Secure Access client for MacOS prior to 14.50. Attackers with control of a modified server can force the client to dump the contents of a small portion of memory to the lo...
CVE-2026-33447
- EPSS 0.25%
- Veröffentlicht 30.04.2026 19:43:27
- Zuletzt bearbeitet 05.05.2026 02:26:55
CVE-2026-33447 is a buffer overflow in a message parsing function of the Secure Access client prior to 14.50. Attackers with control of a modified server can send a special packet that can overwrite a small portion of memory conceivably leading to...
CVE-2026-33446
- EPSS 0.29%
- Veröffentlicht 30.04.2026 19:36:37
- Zuletzt bearbeitet 05.05.2026 02:19:56
CVE-2026-33446 is a buffer overflow in the authentication sub-system of the Secure Access client prior to 14.50. Attackers with control of a modified server can send a special packet that can overwrite a small portion of memory conceivably leading...
CVE-2026-0519
- EPSS 0.12%
- Veröffentlicht 17.01.2026 01:13:59
- Zuletzt bearbeitet 02.02.2026 16:04:56
In Secure Access 12.70 and prior to 14.20, the logging subsystem may write an unredacted authentication token to logs under certain configurations. Any party with access to those logs could read the token and reuse it to access an integrated syste...
CVE-2026-0518
- EPSS 0.15%
- Veröffentlicht 17.01.2026 01:09:29
- Zuletzt bearbeitet 02.02.2026 16:03:47
CVE-2026-0518 is a cross-site scripting vulnerability in versions of Secure Access prior to 14.20. An attacker with administrative privileges can interfere with another administrator’s use of the console.
CVE-2026-0517
- EPSS 0.3%
- Veröffentlicht 17.01.2026 01:04:55
- Zuletzt bearbeitet 02.02.2026 16:01:42
CVE-2026-0517 is a denial-of-service vulnerability in versions of Secure Access Server prior to 14.20. An attacker can send a specially crafted packet to a server and cause the server to crash
CVE-2025-59596
- EPSS 0.2%
- Veröffentlicht 04.11.2025 22:51:31
- Zuletzt bearbeitet 10.02.2026 17:42:15
CVE-2025-59596 is a denial-of-service vulnerability in Secure Access Windows client versions 12.0 to 14.10 that is addressed in version 14.12. If a local networking policy is active, attackers on an adjacent network may be able to send a crafted p...
CVE-2025-59595
- EPSS 0.34%
- Veröffentlicht 04.11.2025 22:46:38
- Zuletzt bearbeitet 08.12.2025 16:17:48
CVE-2025-59595 is an internally discovered denial of service vulnerability in versions of Secure Access prior to 14.12. An attacker can send a specially crafted packet to a server in a non-default configuration and cause the server to crash.