CatchPulse – Multiple Vulnerabilities including Improper Access Control, Unprivileged SYSTEM-Level Operations and Denial of Service
6 August 2026
Multiple vulnerabilities have been discovered in CatchPulse. SecureAge, the product owner, has rolled out fixes for all reported vulnerabilities. Special thanks to the informer and SecureAge for coordinating through CSA's Responsible Vulnerability Disclosure Policy.
Background
CatchPulse is an endpoint security solution that provide proactive protection, such as cloud anti-virus and application control, for Windows devices.
CVE ID - Description
CVE-2026-55978| 8.4 (High) - An improper access control vulnerability in CatchPulse could allow a non-administrative local attacker to connect to an unrestricted kernel filter communication port and bypass CatchPulse's security policy enforcement.
CVE-2026-55979| 5.2 (Medium) - An improper access control check in CatchPulse's named pipe communication interface could allow an attacker to invoke CatchPulse functions. This is limited to operations that enforce more restrictive security policies.
CVE-2026-55980| 5.5 (Medium) - A denial-of-service vulnerability in CatchPulse could allow an attacker to conduct a stack buffer overrun attack, leading to a denial-of-service condition.
Affected Versions
CatchPulse version 10.10.0 and earlier.
Mitigation
SecureAge, the product owner, has rolled out fixes for all reported vulnerabilities. Users and administrators of affected products are advised to update to the latest versions.
Timeline
2026-06-26 – Vendor Disclosure
2026- 07-28 – Vendor Patched
2026- 08-06 – Public Release
Credit
Discovered by: Mr Ang Kar Min
References
