CVE-2026-15506: Heap-based Buffer Overflow in SecureAge CatchPulse
A heap-based buffer overflow vulnerability exists in SecureAge CatchPulse up to version 10.9.3 in the saappctl.sys driver component. The vulnerability requires local access to exploit and can lead to high-impact consequences. Public exploit details have been disclosed. Upgrading to version 10.10.0 resolves the issue.
AI Analysis
Technical Summary
CVE-2026-15506 is a heap-based buffer overflow vulnerability in an unspecified function within the saappctl.sys driver of SecureAge CatchPulse versions up to 10.9.3. The flaw requires local attacker privileges and does not require user interaction. The vulnerability has a CVSS 4.0 base score of 8.5, indicating high severity with high impact on confidentiality, integrity, and availability. Public exploit information is available. The vendor has addressed this issue in version 10.10.0.
Potential Impact
Successful exploitation of this vulnerability can lead to heap-based buffer overflow, potentially allowing an attacker with local access to compromise system stability or execute arbitrary code with limited privileges. The impact on confidentiality, integrity, and availability is rated high according to the CVSS vector.
Mitigation Recommendations
Upgrade SecureAge CatchPulse to version 10.10.0 or later to remediate this vulnerability. No other mitigations are specified. Since the vulnerability requires local access, restricting local user privileges may reduce risk but does not replace the need for patching.
CVE-2026-15506: Heap-based Buffer Overflow in SecureAge CatchPulse
Description
A heap-based buffer overflow vulnerability exists in SecureAge CatchPulse up to version 10.9.3 in the saappctl.sys driver component. The vulnerability requires local access to exploit and can lead to high-impact consequences. Public exploit details have been disclosed. Upgrading to version 10.10.0 resolves the issue.
CVSS v4.0
Score 8.5high
Affected software
cpe:2.3:a:secureage:catchpulse:*:*:*:*:*:*:*:*AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-15506 is a heap-based buffer overflow vulnerability in an unspecified function within the saappctl.sys driver of SecureAge CatchPulse versions up to 10.9.3. The flaw requires local attacker privileges and does not require user interaction. The vulnerability has a CVSS 4.0 base score of 8.5, indicating high severity with high impact on confidentiality, integrity, and availability. Public exploit information is available. The vendor has addressed this issue in version 10.10.0.
Potential Impact
Successful exploitation of this vulnerability can lead to heap-based buffer overflow, potentially allowing an attacker with local access to compromise system stability or execute arbitrary code with limited privileges. The impact on confidentiality, integrity, and availability is rated high according to the CVSS vector.
Mitigation Recommendations
Upgrade SecureAge CatchPulse to version 10.10.0 or later to remediate this vulnerability. No other mitigations are specified. Since the vulnerability requires local access, restricting local user privileges may reduce risk but does not replace the need for patching.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-07-12T05:44:41.811Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a540f1668715ace435c9c2e
Added to database: 07/12/2026, 22:03:02 UTC
Last enriched: 07/20/2026, 19:13:20 UTC
Last updated: 08/26/2026, 22:52:08 UTC
Views: 151
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.