Seppmail
Seppmail Secure Email Gateway: vulnerabilities and CVEs
Seppmail Secure Email Gateway has 24 published vulnerabilities, 24 of them in the last 12 months. 3 are rated critical and 0 are listed by CISA as actively exploited.
CVEs24
Last 12 months24
Critical3
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-84832 | High (8.6) | 0.64% | — | Sep 3, 2026 | SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import workflow without adequate validation. An attacker with a privileged API token can execute arbitrary commands… |
| CVE-2026-84831 | High (7.7) | 0.47% | — | Sep 3, 2026 | SEPPmail Secure Email Gateway before 15.0.7 creates a fully privileged session before required multi-factor authentication enrollment is completed. An attacker with the password for an MFA-required but unenrolled… |
| CVE-2026-84830 | High (8.6) | 1.2% | — | Sep 3, 2026 | SEPPmail Secure Email Gateway before 15.0.7 contains a command injection vulnerability that allows authenticated administrators to execute commands with elevated privileges. |
| CVE-2026-9592 | High (7.5) | 0.24% | — | Jul 17, 2026 | SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15.0.4.2 allows an attacker to replay & hijack a user session in the GINA web portal, as the session token is disclosed inside the URL and a HTTP header. |
| CVE-2026-7864 | Medium (6.9) | 0.54% | — | May 8, 2026 | SEPPmail Secure Email Gateway before version 15.0.4 exposes server environment variables through an unauthenticated endpoint in the new GINA UI, allowing remote attackers to obtain sensitive system information. |
| CVE-2026-44129 | High (8.3) | 0.73% | — | May 8, 2026 | SEPPmail Secure Email Gateway before version 15.0.4 contains a server-side template injection vulnerability in the new GINA UI because an endpoint accepts attacker-controlled template, allowing remote attackers to… |
| CVE-2026-44128 | Critical (9.3) | 0.73% | — | May 8, 2026 | SEPPmail Secure Email Gateway before version 15.0.2.1 allows unauthenticated remote code execution in the new GINA UI because an endpoint passes attacker-controlled input from a parameter to Perl's eval. |
| CVE-2026-44127 | High (8.8) | 0.54% | — | May 8, 2026 | SEPPmail Secure Email Gateway before version 15.0.4 contains an unauthenticated path traversal vulnerability in the identifier parameter of /api.app/attachment/preview that allows remote attackers to read arbitrary… |
| CVE-2026-44126 | Critical (9.2) | 0.76% | — | May 8, 2026 | SEPPmail Secure Email Gateway before version 15.0.4 insecurely deserializes untrusted data, which can be reached from the new GINA UI and may allow unauthenticated remote attackers to execute code via a crafted… |
| CVE-2026-44125 | Critical (9.3) | 0.53% | — | May 8, 2026 | SEPPmail Secure Email Gateway before version 15.0.4 fails to enforce authorization checks for multiple endpoints in the new GINA UI, allowing unauthenticated remote attackers to access functionality that should require… |
| CVE-2026-29144 | High (7.8) | 0.35% | — | Apr 2, 2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge security tags using Unicode lookalike characters. |
| CVE-2026-29143 | High (7.8) | 0.43% | — | Apr 2, 2026 | SEPPmail Secure Email Gateway before version 15.0.3 does not properly authenticate the inner message of S/MIME-encrypted MIME entities, allowing an attacker to control trusted headers. |
| CVE-2026-29142 | Medium (6.3) | 0.19% | — | Apr 2, 2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to forge a GINA-encrypted email. |
| CVE-2026-29141 | High (7.7) | 0.35% | — | Apr 2, 2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge tags such as [signed OK]. |
| CVE-2026-29140 | High (7.7) | 0.19% | — | Apr 2, 2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to cause attacker-controlled certificates to be used for future encryption to a victim by adding the certificates to S/MIME signatures. |
| CVE-2026-29139 | High (7.8) | 0.48% | — | Apr 2, 2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows account takeover by abusing GINA account initialization to reset a victim account password. |
| CVE-2026-29138 | Medium (6.3) | 0.37% | — | Apr 2, 2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted email address to claim another user's PGP signature as their own. |
| CVE-2026-29137 | Medium (5.3) | 0.31% | — | Apr 2, 2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to hide security tags from users by crafting a long subject. |
| CVE-2026-29136 | Medium (5.3) | 0.16% | — | Apr 2, 2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to inject HTML into notification emails about new CA certificates. |
| CVE-2026-29135 | Medium (5.3) | 0.42% | — | Apr 2, 2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to craft a password-tag that bypasses subject sanitization. |
| CVE-2026-29134 | Medium (5.3) | 0.38% | — | Apr 2, 2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an external user to modify GINA webdomain metadata and bypass per-domain restrictions. |
| CVE-2026-29133 | Medium (5.3) | 0.40% | — | Apr 2, 2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to upload PGP keys with UIDs that do not match their email address. |
| CVE-2026-29132 | Medium (6.3) | 0.42% | — | Apr 2, 2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker with access to a victim's GINA account to bypass a second-password check and read protected emails. |
| CVE-2026-29131 | Medium (4.9) | 0.38% | — | Apr 2, 2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted email address to read the contents of emails encrypted for other users. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.