SecureAge CatchPulse Driver saappctl.sys heap-based overflow
Summary
| CVE | CVE-2026-15506 |
|---|---|
| State | PUBLISHED |
| Assigner | VulDB |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-12 22:16:34 UTC |
| Updated | 2026-07-14 17:16:45 UTC |
| Description | A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. The affected element is an unknown function in the library saappctl.sys of the component Driver. Such manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. Upgrading to version 10.10.0 is sufficient to fix this issue. You should upgrade the affected component. The vendor was contacted early about this disclosure. |
Risk And Classification
Primary CVSS: v4.0 7.1 HIGH from [email protected]
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.001840000 probability, percentile 0.081460000 (date 2026-07-14)
Problem Types: CWE-119 | CWE-122 | CWE-122 Heap-based Buffer Overflow | CWE-119 Memory Corruption
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 7.1 | HIGH | CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/C... |
| 4.0 | CNA | DECLARED | 8.5 | HIGH | CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P |
| 3.1 | [email protected] | Secondary | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | DECLARED | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C |
| 3.0 | CNA | DECLARED | 7.8 | HIGH | CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C |
| 2.0 | [email protected] | Secondary | 6.8 | AV:L/AC:L/Au:S/C:C/I:C/A:C | |
| 2.0 | CNA | DECLARED | 6.8 | AV:L/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:OF/RC:C |
CVSS v4.0 Breakdown
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS v3.1 Breakdown
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v3.0 Breakdown
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | SecureAge | CatchPulse | affected 10.9.0 | Not specified |
| CNA | SecureAge | CatchPulse | affected 10.9.1 | Not specified |
| CNA | SecureAge | CatchPulse | affected 10.9.2 | Not specified |
| CNA | SecureAge | CatchPulse | affected 10.9.3 | Not specified |
| CNA | SecureAge | CatchPulse | unaffected 10.10.0 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| jordanhiggins.blog/catchpulse-antivirus-exploits | [email protected] | jordanhiggins.blog | |
| vuldb.com/submit/845584 | [email protected] | vuldb.com | |
| vuldb.com/vuln/377835/cti | [email protected] | vuldb.com | |
| youtu.be/xZqRVWlrah8 | [email protected] | youtu.be | |
| vuldb.com/vuln/377835 | [email protected] | vuldb.com | |
| vuldb.com/cve/CVE-2026-15506 | [email protected] | vuldb.com | |
| github.com/Kalagious/SecureAgeExploit | [email protected] | github.com | |
| vandalsuidaho-my.sharepoint.com/:w:/g/personal/higg2059_vandals_uidaho_edu/IQAcnBjRQKVxQbLuSb... | MITRE | vandalsuidaho-my.sharepoint.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Jordan Higgins (en)
CNA: Jordanhiggins (VulDB User) (en)
CNA: Jordanhiggins (VulDB User) (en)
CNA: VulDB CNA Team (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2026-06-29T00:00:00.000Z | Countermeasure disclosed |
| CNA | 2026-07-12T00:00:00.000Z | Advisory disclosed |
| CNA | 2026-07-12T02:00:00.000Z | VulDB entry created |
| CNA | 2026-07-14T18:40:23.000Z | VulDB entry last update |