Vulnerability Description
A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. The affected element is an unknown function in the library saappctl.sys of the component Driver. Such manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. Upgrading to version 10.10.0 is sufficient to fix this issue. You should upgrade the affected component. The vendor was contacted early about this disclosure.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/Kalagious/SecureAgeExploit
- https://jordanhiggins.blog/catchpulse-antivirus-exploits/
- https://vuldb.com/cve/CVE-2026-15506
- https://vuldb.com/submit/845584
- https://vuldb.com/vuln/377835
- https://vuldb.com/vuln/377835/cti
- https://youtu.be/xZqRVWlrah8
FAQ
What is CVE-2026-15506?
CVE-2026-15506 is a vulnerability with a CVSS score of 7.8 (HIGH). A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. The affected element is an unknown function in the library saappctl.sys of the component Driver. Such manipulation lead...
How severe is CVE-2026-15506?
CVE-2026-15506 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-15506?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.