CVE-2026-40955
CVE-2026-40955 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with
CVSS
3.7
Low
EPSS
0.3%
p25
KEV
—
Exploit Today
7
0-100
Published: Jul 15, 2026 · Last modified: Jul 16, 2026 · CWE-191
0.2%EPSS · 30 days0.3%
2026-08-162026-09-12
CVE-2026-40955 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-13326—4.7%
——1An out-of-bounds read in Qt NFC's language code length parsing allows a physically proximate attacker to cause a denial of service or limited memory disclosure via a crafted NFC tag.3dCVE-2026-819775.5 MED6.9%
——2Acrobat Reader is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.2dCVE-2026-663077.5 HIG49.0%
——15Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network.6dCVE-2026-784536.5 MED58.4%
——18Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information over a network.3dCVE-2026-774885.5 MED23.2%
——7Integer underflow (wrap or wraparound) in SQL Server allows an authorized attacker to disclose information locally.6dCVE-2026-729476.4 MED18.2%
——5Integer underflow (wrap or wraparound) in Windows File History Service allows an authorized attacker to elevate privileges locally.6d