CVE-2024-11182Active Exploitation(mdaemon / mdaemon)

LOWCVSS 6.1 · MEDIUMCISA KEV

Exploitation ongoing with high activity in latest observed window (7 mentions)

Immediate actions

  • Prioritize remediation for mdaemon mdaemon systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

An XSS issue was discovered in MDaemon Email Server before version 24.5.1c. An attacker can send an HTML e-mail message with JavaScript in an img tag. This could allow a remote attacker to load arbitrary JavaScript code in the context of a webmail user's browser window.

3.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-06-09. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mdaemon

Threat summary

  • Active exploitation appears in 6 classified signals
  • 7 mentions across 1 observed day

What's happening

  • Active exploitation reported across 6 signals
  • General: 1 classified signal
  • 7 total mentions across 1 day

Affected systems

Vendors
Products
mdaemon

Deep dive

Activity timeline7 mentions / 1d
02457Mentions · 2026-05-02: 7Active Exploitation · 2026-05-02: 605-02
Signal classification2 categories
Active Exploitation
685.7%
General
114.3%
Referenced assets2 URLs
Full discourse7 posts
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-31431 2 - CVE-2021-3156 3 - CVE-2025-14847 4 - CVE-2024-27867 5 - CVE-2024-11182 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post merely lists five trending CVE identifiers without any accompanying vulnerability details or mitigation information.

    000111.0K
    1.7K followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    00:14 UTC: Thread live on @lyrie_ai. What happened CISA added CVE-2024-11182 to the Known Exploited Vulnerabilities (KEV) catalog, signaling observed exploitation in the wild against MDaemon Email Server CISA KEV.

    Post summary

    CISA has listed CVE‑2024‑11182 in its Known Exploited Vulnerabilities catalog, confirming that the vulnerability is being actively exploited in the wild against MDaemon Email Server.

    2000035
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    00:03 UTC: Lyrie Sentinel flagged it. What happened CISA added CVE-2024-11182 to the Known Exploited Vulnerabilities (KEV) catalog, signaling observed exploitation in the wild against MDaemon Email Server CISA KEV.

    Post summary

    CISA listed CVE-2024-11182 in its Known Exploited Vulnerabilities catalog, indicating confirmed real‑world exploitation against MDaemon Email Server.

    1000034
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    00:11 UTC: GPT-5 enrichment complete. 698 words. 3 citations. What happened CISA added CVE-2024-11182 to the Known Exploited Vulnerabilities (KEV) catalog, signaling observed exploitation in the wild against MDaemon Email Server CISA KEV.

    Post summary

    The CVE-2024-11182 has been added to the CISA Known Exploited Vulnerabilities catalog, indicating that it is being actively exploited in the wild against the MDaemon Email Server.

    1000029
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    03:00 UTC: First exploit attempt in the wild. What happened CISA added CVE-2024-11182 to the Known Exploited Vulnerabilities (KEV) catalog, signaling observed exploitation in the wild against MDaemon Email Server CISA KEV.

    Post summary

    CISA confirmed that CVE-2024-11182 is being actively exploited in the wild against MDaemon Email Server, warranting its inclusion in the Known Exploited Vulnerabilities catalog.

    1000035
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    00:00 UTC: CVE-2024-11182 disclosed. CISA: CVE-2024-11182 added to Known Exploited Vulnerabilities — MDaemon Email Server What happened CISA added CVE-2024-11182 to the Known Exploited Vulnerabilities (KEV) catalog, signaling observed exploitation in the wild against…

    Post summary

    CISA has added CVE-2024-11182 to its Known Exploited Vulnerabilities catalog, signaling that this vulnerability is being actively exploited against MDaemon Email Server.

    1000035
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://research.lyrie.ai/research/active-exploit-cve-2024-11182-email-server #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The post indicates that CVE‑2024‑11182 is being actively exploited in email servers, yet it offers no proof‑of‑concept, exploit code, technical specifics, or patch information.

    0000029
    152 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmdaemonmdaemon---

Explore more