CVE-2026-27442Disclosure(seppmail / seppmail)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch seppmail seppmail systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The GINA web interface in SEPPmail Secure Email Gateway before version 15.0.1 does not properly check attachment filenames in GINA-encrypted emails, allowing an attacker to access files on the gateway.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • seppmail

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 4 mentions (2026-03-04); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
seppmail

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-03-04: 4Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1Patch / Workaround · 2026-03-05: 1Technical Details · 2026-03-04: 3Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 103-0403-0503-06
Signal classification3 categories
Disclosure
350.0%
General
233.3%
Patch
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-044
Disclosure2General2
2026-03-051
Patch1
2026-03-061
Disclosure1
Full discourse6 posts
  • CCB Alert@CCBalert
    Patch

    Warning: Critical vulnerabilities in #SEPPmail Secure Email Gateway (CVE-2026-27441 CVSS: 9.5; CVE-2026-27442 CVSS: 9.3), that may allow OS command execution. #Patch #Patch #Patch

    Post summary

    The tweet alerts to high‑severity CVEs in SEPPmail Secure Email Gateway and urges users to apply patches.

    01010290
    7.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-27442 SEPPmail Secure Email Gateway GINA Interface Arbitrary File Access Vulnerability https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27442

    Post summary

    The text references CVE-2026-27442 as an arbitrary file access vulnerability in SEPPmail Secure Email Gateway’s GINA interface, but offers no additional details such as PoC, exploit, patch, or evidence of active exploitation.

    0001042
    4.0K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    🚨🚨🚨 PDF Password CMDi (CVE-2026-27441) zip attachments path traversal (CVE-2026-27442) SEPPmail Vulnerability Disclosure https://downloads.seppmail.com/extrelnotes/150/ERN15.0.html#seppmail-vulnerability-disclosure

    Post summary

    SEPPmail disclosed two new CVEs (CVE-2026-27441 for PDF Password CMDi and CVE-2026-27442 for zip attachment path traversal) without associated PoC, exploit, or patch details.

    00000529
    6.7K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-27442 📊 Severity: 9.3 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-27442 #CVE-2026-27442 #CVE #Critical  #CyberSecurity #InfoSec https://t.co/kN3YUlRBZj

    Post summary

    A tweet posts a brief CVE alert for CVE-2026-27442, citing its critical severity and linking only to the NVD entry; no additional exploit, patch, or technical details are provided.

    0000038
    64 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-27442 The GINA web interface in SEPPmail Secure Email Gateway before version 15.0.1 does not properly check attachment filenames in GINA-encrypted emails, allowing an attac… https://www.cve.org/CVERecord?id=CVE-2026-27442 ----- Traducción: CVE-2026-27442 La … http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑27442, describing a filename validation flaw in SEPPmail’s GINA web interface, but provides no PoC, exploit, or patch details.

    0000027
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27442 The GINA web interface in SEPPmail Secure Email Gateway before version 15.0.1 does not properly check attachment filenames in GINA-encrypted emails, allowing an attac… https://www.cve.org/CVERecord?id=CVE-2026-27442

    Post summary

    The text announces a vulnerability in SEPPmail Secure Email Gateway’s GINA web interface that fails to validate attachment filenames in GINA‑encrypted emails, potentially enabling exploitation.

    00000169
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appseppmailseppmail---

Explore more