HomeSecuritySEPPMail Gateway: 7 critical vulnerabilities allow RCE and access to emails

SEPPMail Gateway: 7 critical vulnerabilities allow RCE and access to emails

Seven critical security vulnerabilities have been discovered in SEPPMail Secure E-Mail Gateway, an enterprise email security solution, that could be exploited to achieve remote code execution and allow an attacker to read arbitrary emails from the virtual device. InfoGuard Labs – Dario Weiss, Manuel Feifel and Olivier Becker – highlighted that these vulnerabilities could be exploited to read all email traffic or as an entry point into the internal network. The discovery of these vulnerabilities highlights the severity of the risks facing enterprise email security solutions, as SEPPMail is widely used by organizations to protect against spam, phishing and malware.

See also: Cisco Secure FMC: Vulnerability allows RCE attacks

SEPPMail

The most severe of the vulnerabilities is CVE-2026-2743 with a CVSS score of 10.0, a path traversal vulnerability in the large file transfer (LFT) function of the SEPPMail User Web Interface. This vulnerability could allow arbitrary file writing, resulting in remote code execution. In a hypothetical attack scenario, a malicious actor could exploit this vulnerability to overwrite the system's syslog configuration and ultimately obtain a Perl-based reverse shell. The maximum CVSS score of 10.0 makes this vulnerability extremely dangerous, as it allows complete control of the device without any authentication requirements.

CVE -2026-7864 with a CVSS score of 6.9 concerns a sensitive system information exposure that leaks server environment variables via an unauthenticated endpoint in the new GINA UI. Meanwhile, CVE-2026-44125 with a CVSS score of 9.3 concerns a lack of authorization checking for multiple endpoints in the new GINA UI, allowing unauthenticated remote attackers to gain access to functionality that would otherwise require a valid session. The new GINA UI appears to be particularly problematic, as many of the vulnerabilities are located in this specific part of the interface.

See also: Apache MINA: Vulnerabilities allow RCE attacks

SEPPMail Gateway: 7 critical vulnerabilities allow RCE and access to emails

CVE -2026-44126 with a CVSS score of 9.2 is an untrusted data deserialization vulnerability that allows unauthenticated remote attackers to execute code via a crafted serialized object. This type of vulnerability is particularly dangerous as it allows arbitrary code execution without any prior access to the system. CVE-2026-44127 with a CVSS score of 8.8 is an unauthenticated path traversal vulnerability in “/api.app/attachment/preview” that allows remote attackers to read arbitrary local files and cause files in the targeted directory to be deleted with the permissions of the “api.app” process.

CVE -2026-44128 with a CVSS score of 9.3 is an eval injection vulnerability that allows unauthenticated remote code execution by exploiting the fact that the “/api.app/template” function directly passes the user-supplied upldd parameter to a Perl eval() without any sanitization. This practice is a classic example of poor programming practice, as using eval() with unfiltered user data is known to lead to code injection attacks. Finally, CVE-2026-44129 with a CVSS score of 8.3 concerns improper neutralization of special elements used in the template engine, allowing remote attackers to execute arbitrary template expressions.

See also: TP-Link patches vulnerabilities affecting Omada Gateways

SEPPMail Gateway: 7 critical vulnerabilities allow RCE and access to emails

Organizations using SEPPMail should immediately apply available security updates and restrict access to the administrative interface to trusted management networks only. Additionally, it is recommended to review logs for unauthorized configuration changes, rotate credentials and API, and implement multi-layered email security that does not rely solely on the gateway. Organizations should also consider that all email traffic passing through affected devices may have been exposed, and take appropriate measures to assess the impact, according to the source.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS