CVE-2026-33447Disclosure(absolute / secure_access)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch absolute secure_access systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

CVE-2026-33447 is a buffer overflow in a message parsing function of the Secure Access client prior to 14.50. Attackers with control of a modified server can send a special packet that can overwrite a small portion of memory conceivably leading to memory corruption or denial of service.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • secure_access

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-04-30); latest day: 2
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
secure_access

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-04-30: 2Mentions · 2026-05-02: 1Mentions · 2026-05-12: 2Patch / Workaround · 2026-05-02: 1Technical Details · 2026-04-30: 2Technical Details · 2026-05-02: 1Technical Details · 2026-05-12: 104-3005-0205-12
Signal classification2 categories
Disclosure
360.0%
General
240.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-302
Disclosure2
2026-05-021
Disclosure1
2026-05-122
General2
Full discourse5 posts
  • Lyrie.ai@lyrie_ai
    General

    Unpopular opinion: The cybersecurity industry is selling you dashboards. CRITICAL: CVE-2026-33447 (CVSS 9.8) — absolute secure access

    Post summary

    The tweet merely names CVE-2026-33447 with a CVSS 9.8 score, offering no additional exploitation, PoC, or patch details.

    1000042
    210 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33447 CVE-2026-33447 is a buffer overflow in a message parsing function of the Secure Access client prior to 14.50. Attackers with control of a modified server can send a… https://www.cve.org/CVERecord?id=CVE-2026-33447

    Post summary

    The post announces a buffer overflow vulnerability (CVE-2026-33447) in Secure Access client versions older than 14.50, allowing remote attackers with a modified server to exploit it.

    00010143
    57.4K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-33447-absolute-secure-access #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    Only a URL and hashtags are present, providing no substantive content about the CVE, thus the post is classified as a general mention.

    0000020
    210 followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    CVE-2026-33447: Unpatched buffer overflow in Secure Access client <14.50. Rogue server sends oversized packet, corrupts memory, crashes client. AV:N/AC:L/PR:N/A:H. Patch now. #DevSecOps #CVE #BufferOverflow #infosec #cybersecurity #git info: https://www.valtersit.com/cve/2026/04/cve-2026-33447/

    Post summary

    An unpatched buffer overflow in Secure Access client <14.50 was disclosed with CVSS details, and a patch has been made available.

    0000099
    889 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-33447 CVE-2026-33447 is a buffer overflow in a message parsing function of the Secure Access client prior to 14.50. Attackers with control of a modified server can send a… https://www.cve.org/CVERecord?id=CVE-2026-33447 ----- Traducción: CVE-2026-33447 es … http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑33447, detailing a buffer overflow in Secure Access client’s message parser pre‑14.50, but offers no PoC, exploit code, or patch information.

    0000014
    75 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appabsolutesecure_access---

Explore more