CVE-2026-40951: Memory corruption in Secure Access Windows clients prior to 14.50
Published Apr 30, 2026
·Updated
CVE-2026-40951 is a memory corruption vulnerability on Secure Access Windows clients prior to 14.50. Attackers with local control of the Windows client can send malformed data to an API and trigger a denial of service.
Affected Software
3 affected components
Secure Access Windows client<14.50
All of the following
Absolute Secure Access<14.50
Microsoft Windows
Event History
Apr 30, 2026
CVE Published
via MITRE·08:22 PM
Data Sourced
via MITRE·08:22 PM
Description
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-40951?
CVE-2026-40951 is categorized as a memory corruption vulnerability that can lead to denial of service.
2
How do I fix CVE-2026-40951?
To fix CVE-2026-40951, upgrade to Secure Access Windows client version 14.50 or later.
3
What software is affected by CVE-2026-40951?
CVE-2026-40951 affects Secure Access Windows clients prior to version 14.50.
4
What type of attacks can exploit CVE-2026-40951?
CVE-2026-40951 can be exploited by attackers with local control sending malformed data to an API.
5
What is the potential impact of CVE-2026-40951?
The potential impact of CVE-2026-40951 includes triggering a denial of service on the affected Secure Access Windows clients.