---
id: CVE-2026-15506
title: >-
  A security vulnerability has been detected in SecureAge CatchPulse up to
  10.9.3
summary: >-
  A security vulnerability has been detected in SecureAge CatchPulse up to
  10.9.3. The affected element is an unknown function in the library
  saappctl.sys of the component Driver. Such manipulation leads to heap-based
  buffer overflow. An a…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-119
  - CWE-122
published: '2026-07-12'
updated: '2026-07-12'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-15506'
references:
  - url: >-
      https://vandalsuidaho-my.sharepoint.com/:w:/g/personal/higg2059_vandals_uidaho_edu/IQAcnBjRQKVxQbLuSb5CI-8nAdTRuWZMO0jEuQ5PUQT7__s?e=4sd123
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-15506'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/845584'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/377835'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/377835/cti'
    label: cna@vuldb.com
  - url: 'https://youtu.be/xZqRVWlrah8'
    label: cna@vuldb.com
tags:
  - nvd
ingestedAt: '2026-07-12T22:22:05.774Z'
epss: 0.00197
epssPercentile: 0.08438
---

## Overview

A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. The affected element is an unknown function in the library saappctl.sys of the component Driver. Such manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
