SecureAge CatchPulse Security Advisories

Three vulnerabilities affecting CatchPulse 10.10.0 and earlier, researched and responsibly disclosed by Ang Kar Min.

Public disclosure: 6 August 2026

CVE-2026-55978 · 8.4 High

Improper Access Control in IOCTL Handler Leading to Security Policy Bypass / SAAppWhitelistingPort

Read the advisory →

CVE-2026-55979 · 5.2 Medium

Named Pipe NULL DACL / unprivileged SYSTEM-level operations

Read the advisory →

CVE-2026-55980 · 5.5 Medium

Stack Buffer Overrun / saappsvc.exe service denial of service

Read the advisory →