CVE-2026-40949: Buffer overflow in Windows clients prior to 14.50
Published Apr 30, 2026
·Updated
CVE-2026-40949 is a buffer overflow vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can use it to trigger a denial of service.
Affected Software
3 affected components
Secure Access Windows client<14.50
All of the following
Absolute Secure Access<14.50
Microsoft Windows
Event History
Apr 30, 2026
CVE Published
via MITRE·08:16 PM
Data Sourced
via MITRE·08:16 PM
Description
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-40949?
CVE-2026-40949 is classified as a high-severity vulnerability due to its potential for causing a denial of service.
2
What versions of Secure Access Windows client are affected by CVE-2026-40949?
CVE-2026-40949 affects all versions of the Secure Access Windows client prior to 14.50.
3
How do I fix CVE-2026-40949?
To fix CVE-2026-40949, upgrade the Secure Access Windows client to version 14.50 or later.
4
What type of attack can exploit CVE-2026-40949?
CVE-2026-40949 can be exploited by attackers with local control of the Windows client to trigger a denial of service.
5
Can CVE-2026-40949 lead to data loss?
While CVE-2026-40949 primarily causes a denial of service, it may indirectly lead to data loss if critical services become unavailable.