CVE-2026-11459

LOW

CVSS v3.1: 3.3 · EPSS: 0.0001 (1.5 percentile)

No user interactionInformation Exposure

Source data as of:

At a glance

Severity
LOW
CVSS
3.3 v3.1 · NVD
EPSS
0.0001 (1.5 percentile) · FIRST.org
CISA KEV
No
Type
Information Exposure · NVD CWE
Attack conditions (CVSS vector)
No user interaction · Source: NVD Vector
Published
2026-06-07 · Modified: 2026-06-07

CVSS / EPSS / KEV

CVSS v3.1 3.3 / 10 LOW Source: NVD
CVSS v4.0 1.9 / 10 LOW Source: NVD
EPSS 0.0001 1.5 percentile Source: FIRST.org
CISA KEV No Source: CISA

Source — CVSS: NVD · EPSS: FIRST.org · KEV: CISA. Data & Sources

Description

A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.1. Impacted is an unknown function in the library saappctl.sys of the component IOCTL Handler. The manipulation leads to information disclosure. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Record details

CVE ID
CVE-2026-11459
CVSS (v3.1)
3.3 (LOW)
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability subscore
1.8
Impact subscore
1.4
EPSS
0.0001 (1.5 percentile) — 2026-06-08
CISA KEV
No
Weakness (CWE)
CWE-200, CWE-284
Affected configurations (CPE)
0
Published
2026-06-07
Modified
2026-06-07
Status
Received

References

Reference URLs as listed by NVD, grouped by a mechanical match on the link's host/pattern. Labels describe the link type only.