
CVE-2026-29138 SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted email address to claim another user's PGP signature as their own. https://www.cve.org/CVERecord?id=CVE-2026-29138
Post summary
The post announces a new vulnerability (CVE‑2026‑29138) in SEPPmail Secure Email Gateway that allows attackers to fake PGP signatures via specially crafted email addresses; no exploitation, PoC, patch, or false positive claim is present.
