📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global phishing Cross-sector HIGH 4h Global vulnerability Enterprise Software / ERP Systems CRITICAL 25m Global vulnerability IT Infrastructure CRITICAL 1h Global vulnerability Technology and Software Development HIGH 2h Global vulnerability Enterprise IT and Government CRITICAL 2h Global ransomware Multiple Sectors / Enterprise CRITICAL 3h Global general Technology and Legal MEDIUM 3h Global ransomware Financial Services / Cryptocurrency CRITICAL 4h Global general Industrial Control Systems / Operational Technology HIGH 5h Global apt Managed Service Providers (MSPs) / IT Services HIGH 6h Global phishing Cross-sector HIGH 4h Global vulnerability Enterprise Software / ERP Systems CRITICAL 25m Global vulnerability IT Infrastructure CRITICAL 1h Global vulnerability Technology and Software Development HIGH 2h Global vulnerability Enterprise IT and Government CRITICAL 2h Global ransomware Multiple Sectors / Enterprise CRITICAL 3h Global general Technology and Legal MEDIUM 3h Global ransomware Financial Services / Cryptocurrency CRITICAL 4h Global general Industrial Control Systems / Operational Technology HIGH 5h Global apt Managed Service Providers (MSPs) / IT Services HIGH 6h Global phishing Cross-sector HIGH 4h Global vulnerability Enterprise Software / ERP Systems CRITICAL 25m Global vulnerability IT Infrastructure CRITICAL 1h Global vulnerability Technology and Software Development HIGH 2h Global vulnerability Enterprise IT and Government CRITICAL 2h Global ransomware Multiple Sectors / Enterprise CRITICAL 3h Global general Technology and Legal MEDIUM 3h Global ransomware Financial Services / Cryptocurrency CRITICAL 4h Global general Industrial Control Systems / Operational Technology HIGH 5h Global apt Managed Service Providers (MSPs) / IT Services HIGH 6h
Vulnerabilities

CVE-2026-40629

High
CWE-770 — Weakness Type
Published: May 13, 2026  ·  Modified: May 20, 2026  ·  Source: NVD
CVSS v3
7.5
🔗 NVD Official
📄 Description (English)

When SSL profiles are configured on a virtual server, undisclosed traffic can cause the virtual server to stop processing new client connections.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

🤖 AI Executive Summary

CVE-2026-40629 is a high-severity denial-of-service vulnerability affecting SSL-configured virtual servers that can cause service interruption when processing undisclosed traffic. The vulnerability has a CVSS score of 7.5 and exploits resource exhaustion mechanisms (CWE-770), making it a significant threat to organizations relying on SSL-terminated services. Currently, no patch is available, requiring immediate implementation of compensating controls and monitoring strategies.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 20, 2026 15:02
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability poses significant risk to Saudi banking sector (SAMA-regulated institutions), government agencies (NCA oversight), and telecommunications providers (STC, Mobily) that heavily rely on SSL-terminated virtual servers for secure client connections. Energy sector (ARAMCO, SEC) and healthcare organizations using load balancers with SSL profiles are also at elevated risk. The DoS impact could disrupt critical financial transactions, government services, and essential infrastructure operations during peak traffic periods.
🏢 Affected Saudi Sectors
Banking and Financial Services Government and Public Administration Telecommunications Energy and Utilities Healthcare E-commerce and Retail
⚖️ Saudi Risk Score (AI)
7.8
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Inventory all virtual servers with SSL profiles across your infrastructure
2. Implement rate limiting and connection throttling on SSL-configured virtual servers
3. Deploy traffic filtering rules to identify and block malformed or undisclosed traffic patterns
4. Enable detailed logging of SSL connection attempts and failures

COMPENSATING CONTROLS:
1. Configure connection limits per source IP to prevent resource exhaustion
2. Implement WAF/DDoS mitigation rules to filter suspicious traffic before reaching virtual servers
3. Deploy health checks with automatic failover to redundant SSL endpoints
4. Use traffic shaping to limit concurrent SSL connections

DETECTION RULES:
1. Alert on sudden spike in SSL connection rejections or timeouts
2. Monitor for patterns of incomplete SSL handshakes from single sources
3. Track virtual server CPU/memory spikes correlating with SSL traffic anomalies
4. Log and analyze traffic with unusual packet structures or malformed SSL records

MONITORING:
1. Establish baseline metrics for SSL connection success rates
2. Set alerts for >20% increase in SSL connection failures
3. Implement real-time alerting for virtual server becoming unresponsive
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. قم بحصر جميع الخوادم الافتراضية مع ملفات تعريف SSL عبر البنية التحتية
2. تطبيق تحديد معدل الاتصال على الخوادم الافتراضية المزودة بـ SSL
3. نشر قواعد تصفية حركة المرور لتحديد وحجب أنماط حركة المرور غير المحددة
4. تفعيل تسجيل مفصل لمحاولات واتصالات SSL

الضوابط البديلة:
1. تكوين حدود الاتصال لكل عنوان IP مصدر
2. تطبيق قواعد تخفيف DDoS/WAF قبل وصول حركة المرور إلى الخوادم
3. نشر فحوصات صحية مع الفشل التلقائي إلى نقاط نهاية SSL احتياطية
4. استخدام تشكيل حركة المرور لتحديد اتصالات SSL المتزامنة

قواعد الكشف:
1. تنبيهات عند حدوث ارتفاع مفاجئ في رفض أو انقطاع اتصالات SSL
2. مراقبة أنماط مصافحات SSL غير المكتملة من مصادر واحدة
3. تتبع ارتفاعات CPU/الذاكرة للخادم الافتراضي المرتبطة بشذوذ حركة SSL
4. تسجيل وتحليل حركة المرور ذات الهياكل غير العادية أو سجلات SSL المشوهة
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.12.6.1 - Management of technical vulnerabilities ECC 2024 A.12.2.1 - Change management procedures ECC 2024 A.8.2.3 - User access management and monitoring
🔵 SAMA CSF
SAMA CSF ID.BE-5 - Organizational resilience objectives SAMA CSF PR.DS-6 - Integrity checking mechanisms SAMA CSF DE.CM-1 - Network monitoring and anomaly detection
🟡 ISO 27001:2022
ISO 27001:2022 A.12.2.1 - Change management ISO 27001:2022 A.12.6.1 - Management of technical vulnerabilities ISO 27001:2022 A.8.2.1 - User registration and de-registration
🟣 PCI DSS v4.0.1
PCI DSS 6.2 - Security patches and updates PCI DSS 11.2 - Vulnerability scanning and assessment
📊 CVSS Score
7.5
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredN — None / Network
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityN — None / Network
IntegrityN — None / Network
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score7.5
CWECWE-770
EPSS0.10%
Exploit No
Patch ✗ No
Published 2026-05-13
Source Feed nvd
🇸🇦 Saudi Risk Score
7.8
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-770
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.