Post-quantum cryptography is here — SecureAge is prepared.

Vulnerability Disclosures

Security Advisories

Stay protected, stay informed. A record of vulnerabilities we've identified, resolved, and disclosed—so you can take action.

Showing all security advisories.

Published Date 

Advisory

Product

Severity

Status

6 Aug 2026

CatchPulse

Medium

Resolved

6 Aug 2026

CatchPulse

Medium

Resolved

6 Aug 2026

CatchPulse

High

Resolved

3 Dec 2025

SecureAge Security Suite

High

Resolved

[Resolved] Escalation of Privilege in SecureAge Security Suite

A privilege escalation vulnerability has been identified and resolved. Users on affected versions should update immediately.

Vulnerability Overview

A privilege escalation vulnerability was identified in SecureAge Security Suite for Windows. A locally logged-in user could exploit this flaw to create, modify, or delete files in privileged system locations — actins that should only be available to administrators. This vulnerability has been fully resolved in the versions listed below. 

Technical details
The vulnerability stems from how SecureAge Security Suite handles symbolic links during normal operation. A local attacker could create specific symbolic links n the system. When the SecureAge software ran, it would follow  those links and perform file operations in privileged Windows path locations . This could allow an unprivileged user to plant, alter, or remove files they would not ordinarily have access to.
Affected & Fixed Versions
Product Vulnerable Version Fixed Version Status

SecureAge Security Suite

7.0.37 and earlier

7.0.38

✓Resolved

SecureAge Security Suite

7.1.10 and earlier

7.1.11

✓Resolved

SecureAge Security Suite

8.0.17 and earlier

8.0.18

✓Resolved

SecureAge Security Suite

8.1.17 and earlier
8.1.18

✓Resolved

Recommended Action

Update to the fixed version or any later release immediately. No workaround is available—patching is the only resolution. If you are unsure which version you are running, open SecureAge Security Suite and check Help>About. Contact our support team if you need assistance with the update process. 

Acknowledgement

SecureAge thanks GovTech Cyber Security Group (CSG) and CSA Cyber Security Engineering Centre (CSEC) for responsibly disclosing this issue through coordinated vulnerability disclosure. 

Advisory Details
Status

✓ Resolved

Severity

High

Product

SecureAge Security Suite

Platform

Windows

Attack Type

Local

[CVE-2026-55980] Stack Buffer Overrun

CVE ID

CVE-2026-55980 | 5.5 (Medium)

A denial-of-service vulnerability in CatchPulse could allow an attacker to conduct a stack buffer overrun attack, leading to a denial-of-service condition. 

Affected & Fixed Versions
Product Vulnerable Version Fixed Version Status

CatchPulse 

10.10.0 and earlier
10.10.1

✓Resolved

Recommended Action

Users and administrators of affected products are advised to update to the latest versions.

Acknowledgement

SecureAge thanks Mr Ang Kar Min for responsibly disclosing this issue through coordinated vulnerability disclosure.

Advisory Details
Status

✓ Resolved

Severity

Medium

Product

CatchPulse

Platform

Windows

Attack Type

Local

[CVE-2026-55979] Named Pipe NULL DACL

CVE ID

CVE-2026-55979 | 5.2 (Medium)

An improper access control check in CatchPulse’s named pipe communication interface could allow an attacker to invoke CatchPulse functions. It is limited to operations that enforce more restrictive security policies.

Affected & Fixed Versions
Product Vulnerable Version Fixed Version Status

CatchPulse 

10.10.0 and earlier
10.10.1

✓Resolved

Recommended Action

Users and administrators of affected products are advised to update to the latest versions.

Acknowledgement

SecureAge thanks Mr Ang Kar Min for responsibly disclosing this issue through coordinated vulnerability disclosure.

Advisory Details
Status

✓ Resolved

Severity

Medium

Product

CatchPulse

Platform

Windows

Attack Type

Local

[CVE-2026-55978] Improper Access Control in IOCTL Handler Leading to Security Policy Bypass

CVE ID

CVE-2026-55978 | 8.4 (High)

An improper access control vulnerability in CatchPulse could allow a non-administrative local attack to connect to an unrestricted kernel filter communication port and bypass CatchPulse’s security policy Enforcement.

Affected & Fixed Versions
Product Vulnerable Version Fixed Version Status

CatchPulse 

v10.10.0 and earlier
10.10.1

✓Resolved

Recommended Action

Users and administrators of affected products are advised to update to the latest versions.

Acknowledgement

SecureAge thanks Mr Ang Kar Min for responsibly disclosing this issue through coordinated vulnerability disclosure.

Advisory Details
Status

✓ Resolved

Severity

High

Product

CatchPulse

Platform

Windows

Attack Type

Local