CVE-2026-2743Disclosure(seppmail / seppmail)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch seppmail seppmail systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Arbitrary File Write via Path Traversal upload to Remote Code Execution in SeppMail User Web Interface. The affected feature is the large file transfer (LFT). This issue affects SeppMail: 15.0.2.1 and before

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-434

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • seppmail

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 6 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-05-20); latest day: 1
  • 7 total mentions across 6 days

Affected systems

Vendors
Products
seppmail

Deep dive

Activity timeline7 mentions / 6d
01122Mentions · 2026-03-05: 1Mentions · 2026-05-18: 1Mentions · 2026-05-20: 2Mentions · 2026-05-21: 1Mentions · 2026-05-26: 1Mentions · 2026-06-08: 1PoC Mentioned / Linked · 2026-05-18: 1Active Exploitation · 2026-06-08: 1Patch / Workaround · 2026-05-20: 1Patch / Workaround · 2026-05-21: 1Technical Details · 2026-03-05: 1Technical Details · 2026-05-18: 1Technical Details · 2026-05-20: 1Technical Details · 2026-05-21: 1Technical Details · 2026-05-26: 1Technical Details · 2026-06-08: 103-0505-1805-2005-2105-2606-08
Signal classification4 categories
Disclosure
342.9%
Patch
228.6%
General
114.3%
Active Exploitation
114.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-051
Disclosure1
2026-05-181
Disclosure1
2026-05-202
General1Patch1
2026-05-211
Patch1
2026-05-261
Disclosure1
2026-06-081
Active Exploitation1
Full discourse7 posts
  • InfoGuard Labs@InfoGuard_Labs
    Disclosure

    New research: We audited SEPPmail's virtual appliance & found critical issues. Our post covers CVE-2026-2743 (RCE via syslog.conf) & CVE-2026-44128 (Perl injection) that let attackers read all mails or compromise the appliance. -> https://labs.infoguard.ch/posts/seppmail_secure_e-mail_gateway_rce_vulnerabilities_cve-2026-2743_cve-2026-7864_cve-2026-44127_cve-2026-44128/

    Post summary

    The post announces critical vulnerabilities (CVE-2026-2743 and CVE-2026-44128) in SEPPmail’s appliance, detailing RCE via syslog.conf and Perl injection, but offers no explicit PoC code, exploit tools, patches, or evidence of active exploitation.

    116027143.7K
    299 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVE-2026-2743. Source: X search for CVE-2026 critical Posted: 2026-05-18T14:19:37.000Z Likes: 13

    Post summary

    The post simply references a CVE ID without providing any technical details, exploitation info, or remediation guidance.

    1001042
    226 followersView on X
  • 城咲子@情シス部セキュリティ担当@jo_sekiko
    Patch

    メールセキュリティ製品にCVSS 10.0。 CVE-2026-2743(SEPPmail) ファイル転送機能にパストラバーサル→RCE。 ✅ 即時パッチ適用 ✅ 外部公開ポートの確認 「守るための製品が入口になる」を想定した設計が必要。 #情シス #メールセキュリティ

    Post summary

    The post highlights CVE-2026-2743 with a path traversal that enables RCE and a CVSS of 10.0, urging immediate patch deployment and external port verification to mitigate the threat.

    00010113
    4.3K followersView on X
  • ThreatCluster@threatcluster
    Active Exploitation

    CVE-2026-2743 is being actively exploited as a remote code execution vulnerability in SeppMail versions 15.0.2.1 and earlier with a CVSS score of 9.8, http://Strobes.Co reported. https://threatcluster.io/cluster/critical-vulnerability-cve-2026-2743-in-seppmail-exposes-use-e49927dd

    Post summary

    CVE-2026-2743 is a high‑severity remote code execution flaw in SeppMail, with reported active exploitation in the wild, but no PoC, exploit code, or patch details are provided.

    0000072
    317 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    SEPPmail Secure E-Mail Gateway に複数の脆弱性:認証不要の RCE とトラフィック傍受 https://iototsecnews.jp/2026/05/19/seppmail-gateway-flaws-expose-organizations-to-rce-and-email-traffic-interception/ 今回の脆弱性の原因は、システムへ渡されるデータのチェックが不十分だったことに起因します。たとえば、脆弱性 CVE-2026-2743 では、アップロードされるファイル名の検証が足りなかったため、本来は書き換えてはいけないシステムの設定ファイルが変更されてしまいます。また、脆弱性 CVE-2026-44128 では、外部からの入力データをそのままプログラムの命令として実行してしまう問題が引き起こされます。このように、ユーザーが入力したデータの安全性を確認せずに処理してしまうことが、リモートからの不正なコマンド実行 (RCE) などの深刻な危険につながります。ご利用のチームは、ご注意ください。 #CVE20262743 #CVE202644127 #CVE202644128 #CVE20267864 #SecureEMailGateway #SEPPmail #Vulnerability

    Post summary

    The article announces multiple CVEs in SEPPmail Secure E‑Mail Gateway, explaining the technical root causes and the resulting remote code execution risk, but it offers no PoC, exploit code, active exploitation reports, patches, or debunking claims.

    0000059
    490 followersView on X
  • SHORT INFO@ShortInfoNews
    Patch

    Every unpatched SEPPmail Secure E-Mail Gateway can be remotely seized and all corporate email read. InfoGuard Labs disclosed 7 flaws May 19, including a CVSS 10.0 path traversal (CVE-2026-2743) and an unauthenticated Perl RCE (CVE-2026-44128). Patched in v15.0.4.

    Post summary

    SEPPmail Secure E‑Mail Gateway is vulnerable to severe path traversal and Perl RCE flaws (CVE-2026-2743, CVE-2026-44128) if unpatched; the vendor released patch v15.0.4 to mitigate these risks.

    000004
    147 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-2743 - SEPPmail User Web Interface Arbitrary File Write to RCE Intel Report: https://ift.tt/UzK82jq

    Post summary

    The alert announces CVE-2026-2743, an SEPPmail vulnerability that allows arbitrary file write leading to remote code execution, and provides a technical description of the issue.

    0000038
    343 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appseppmailseppmail---

Explore more