Vulnerabilities
Summary — last 7 days
New vulnerabilities2,950▲ 8 vs. last week
Critical / high1,450▲ 184 vs. last week
New active exploitation (KEV)5▼ 3 vs. last week
Unscored (no CVSS)272▼ 254 vs. last week
39 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Awaiting Analysis | Critical (9.8) | 0.53% | — | Cisco Secure Email GatewayAICisco Secure Email AND WEB ManagerAI | 9/14/2026 | 9/15/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered… | |
| Awaiting Analysis | High (7.5) | 0.47% | — | Cisco Secure Email GatewayAICisco Secure Email AND WEB ManagerAI | 9/14/2026 | 9/16/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered… | |
| Awaiting Analysis | Critical (9.8) | 0.53% | — | Cisco Secure Email GatewayAICisco Secure Email AND WEB ManagerAI | 9/14/2026 | 9/15/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered… | |
| Awaiting Analysis | Critical (9.8) | 0.62% | — | Cisco Secure Email GatewayAICisco Secure Email AND WEB ManagerAI | 9/14/2026 | 9/15/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered… | |
| Awaiting Analysis | Critical (9.8) | 0.40% | — | Cisco Secure Email GatewayAICisco Secure Email AND WEB ManagerAI | 9/14/2026 | 9/15/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered… | |
| Deferred | High (8.6) | 0.64% | — | Seppmail Secure Email GatewayAI | 9/3/2026 | 9/4/2026 | SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import workflow without adequate validation. An attacker with a privileged API token can execute arbitrary commands with "nobody" privileges. | |
| Deferred | High (7.7) | 0.47% | — | Seppmail Secure Email GatewayAI | 9/3/2026 | 9/3/2026 | SEPPmail Secure Email Gateway before 15.0.7 creates a fully privileged session before required multi-factor authentication enrollment is completed. An attacker with the password for an MFA-required but unenrolled account can access protected functionality without providing a second factor. | |
| Deferred | High (8.6) | 1.2% | — | Seppmail Secure Email GatewayAI | 9/3/2026 | 9/3/2026 | SEPPmail Secure Email Gateway before 15.0.7 contains a command injection vulnerability that allows authenticated administrators to execute commands with elevated privileges. | |
| Deferred | High (7.5) | 0.24% | — | Seppmail Secure Email GatewayAISeppmail CloudAI | 7/17/2026 | 7/17/2026 | SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15.0.4.2 allows an attacker to replay & hijack a user session in the GINA web portal, as the session token is disclosed inside the URL and a HTTP header. | |
| Deferred | Medium (6.9) | 0.54% | — | Seppmail Secure Email GatewayAI | 5/8/2026 | 6/17/2026 | SEPPmail Secure Email Gateway before version 15.0.4 exposes server environment variables through an unauthenticated endpoint in the new GINA UI, allowing remote attackers to obtain sensitive system information. | |
| Deferred | High (8.3) | 0.73% | — | Seppmail Secure Email GatewayAI | 5/8/2026 | 6/17/2026 | SEPPmail Secure Email Gateway before version 15.0.4 contains a server-side template injection vulnerability in the new GINA UI because an endpoint accepts attacker-controlled template, allowing remote attackers to execute arbitrary template expressions and potentially achieve remote code execution depending on the… | |
| Deferred | Critical (9.3) | 0.73% | — | Seppmail Secure Email GatewayAI | 5/8/2026 | 6/17/2026 | SEPPmail Secure Email Gateway before version 15.0.2.1 allows unauthenticated remote code execution in the new GINA UI because an endpoint passes attacker-controlled input from a parameter to Perl's eval. | |
| Deferred | High (8.8) | 0.54% | — | Seppmail Secure Email GatewayAI | 5/8/2026 | 6/17/2026 | SEPPmail Secure Email Gateway before version 15.0.4 contains an unauthenticated path traversal vulnerability in the identifier parameter of /api.app/attachment/preview that allows remote attackers to read arbitrary local files and trigger deletion of files in the targeted directory with the privileges of the api.app… | |
| Deferred | Critical (9.2) | 0.76% | — | Seppmail Secure Email GatewayAI | 5/8/2026 | 6/17/2026 | SEPPmail Secure Email Gateway before version 15.0.4 insecurely deserializes untrusted data, which can be reached from the new GINA UI and may allow unauthenticated remote attackers to execute code via a crafted serialized object. | |
| Deferred | Critical (9.3) | 0.53% | — | Seppmail Secure Email GatewayAI | 5/8/2026 | 6/17/2026 | SEPPmail Secure Email Gateway before version 15.0.4 fails to enforce authorization checks for multiple endpoints in the new GINA UI, allowing unauthenticated remote attackers to access functionality that should require a valid session. | |
| Analyzed | High (7.8) | 0.35% | — | Seppmail Secure Email Gateway | 4/2/2026 | 6/17/2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge security tags using Unicode lookalike characters. | |
| Analyzed | High (7.8) | 0.43% | — | Seppmail Secure Email Gateway | 4/2/2026 | 6/17/2026 | SEPPmail Secure Email Gateway before version 15.0.3 does not properly authenticate the inner message of S/MIME-encrypted MIME entities, allowing an attacker to control trusted headers. | |
| Analyzed | Medium (6.3) | 0.19% | — | Seppmail Secure Email Gateway | 4/2/2026 | 6/17/2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to forge a GINA-encrypted email. | |
| Analyzed | High (7.7) | 0.35% | — | Seppmail Secure Email Gateway | 4/2/2026 | 6/17/2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge tags such as [signed OK]. | |
| Analyzed | High (7.7) | 0.19% | — | Seppmail Secure Email Gateway | 4/2/2026 | 6/17/2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to cause attacker-controlled certificates to be used for future encryption to a victim by adding the certificates to S/MIME signatures. | |
| Analyzed | High (7.8) | 0.48% | — | Seppmail Secure Email Gateway | 4/2/2026 | 6/17/2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows account takeover by abusing GINA account initialization to reset a victim account password. | |
| Analyzed | Medium (6.3) | 0.37% | — | Seppmail Secure Email Gateway | 4/2/2026 | 6/17/2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted email address to claim another user's PGP signature as their own. | |
| Analyzed | Medium (5.3) | 0.31% | — | Seppmail Secure Email Gateway | 4/2/2026 | 6/17/2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to hide security tags from users by crafting a long subject. | |
| Analyzed | Medium (5.3) | 0.16% | — | Seppmail Secure Email Gateway | 4/2/2026 | 6/17/2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to inject HTML into notification emails about new CA certificates. | |
| Analyzed | Medium (5.3) | 0.42% | — | Seppmail Secure Email Gateway | 4/2/2026 | 6/17/2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to craft a password-tag that bypasses subject sanitization. |