CVE-2026-32661Active Exploitation

MEDIUMCVSS 9.3 · CRITICAL

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Stack-based buffer overflow vulnerability exists in GUARDIANWALL MailSuite and GUARDIANWALL Mail Security Cloud (SaaS version). If a remote attacker sends a specially crafted request to the product's web service, arbitrary code may be executed when the product is configured to run pop3wallpasswd with grdnwww user privilege.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 6 classified signals
  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 6 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 7 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-05-14); latest day: 1
  • 7 total mentions across 4 days

Deep dive

Activity timeline7 mentions / 4d
01223Mentions · 2026-05-13: 2Mentions · 2026-05-14: 3Mentions · 2026-05-15: 1Mentions · 2026-05-17: 1Active Exploitation · 2026-05-13: 2Active Exploitation · 2026-05-14: 3Active Exploitation · 2026-05-17: 1Patch / Workaround · 2026-05-14: 3Technical Details · 2026-05-13: 2Technical Details · 2026-05-14: 3Technical Details · 2026-05-15: 1Technical Details · 2026-05-17: 105-1305-1405-1505-17
Signal classification2 categories
Active Exploitation
685.7%
Disclosure
114.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-132
Active Exploitation2
2026-05-143
Active Exploitation3
2026-05-151
Disclosure1
2026-05-171
Active Exploitation1
Full discourse7 posts
  • Autumn Good@autumn_good_35
    Active Exploitation

    🚨🚨🚨 『開発者によると、GUARDIANWALL MailSuite(オンプレミス版)において本脆弱性を悪用した攻撃がすでに確認されている』 2026-05-13 JPCERT/CC CVE-2026-32661 GUARDIANWALL MailSuiteにおけるスタックベースのバッファオーバーフローの脆弱性に関する注意喚起 https://www.jpcert.or.jp/at/2026/at260013.html

    Post summary

    JPCERT reports that CVE-2026-32661 is being exploited in the wild against GUARDIANWALL MailSuite, identified as a stack-based buffer overflow, with no PoC, exploit code, or patch mentioned.

    000611.1K
    6.9K followersView on X
  • Gray Hats@the_yellow_fall
    Active Exploitation

    CVE-2026-32661 exploited in the wild. A 9.8 CVSS flaw in GUARDIANWALL MailSuite allows unauthenticated RCE. Apply Canon's official patches immediately. #MailSecurity #CyberSecurity #InfoSec #RCE #VulnerabilityAlert #CVE #Canon #GUARDIANWALL #ExploitAlert https://securityonline.info/guardianwall-mailsuite-vulnerability-cve-2026-32661-exploited/

    Post summary

    CVE-2026-32661, a 9.8‑CVSS unauthenticated RCE in GUARDIANWALL MailSuite, is actively exploited in the wild, and users are urged to apply Canon's official patches immediately.

    00032535
    12.5K followersView on X
  • Mr.Rabbit@01ra66it
    Active Exploitation

    【「GUARDIANWALL MailSuite」におけるスタックベースのバッファオーバーフローの脆弱性について(JVN#35567473)】 IPAは、キヤノンマーケティングジャパンが提供するGUARDIANWALL MailSuiteに関する脆弱性 CVE-2026-32661 について注意喚起しました。対象はスタックベースのバッファオーバーフローで、攻撃者がWebサービスに細工したリクエストを送信した場合、任意コード実行につながる可能性があります。 重要なのは、GUARDIANWALL MailSuiteオンプレミス版で本脆弱性を悪用した攻撃が既に確認されている点です。メールセキュリティ製品は外部メール、添付、検疫、ログに近い位置にあり、侵害されるとメール経路の信頼性そのものが揺らぎます。 防御側は、対象バージョンの確認、パッチ適用、ベンダー推奨ワークアラウンドを優先してください。適用後も、Webアクセスログ、製品ログ、管理者操作、OSプロセス、外向き通信を侵害済み前提で確認する必要があります。 #GUARDIANWALL #CVE202632661 #IPA #メールセキュリティ #脆弱性対応 #SOC https://www.ipa.go.jp/security/security-alert/2026/20260513-jvn.html

    Post summary

    IPA reports confirmed active exploitation of CVE-2026-32661 in GUARDIANWALL MailSuite, a stack-based buffer overflow that can lead to arbitrary code execution, and urges patching and vendor-suggested workarounds.

    11001521
    3.7K followersView on X
  • Mr.Rabbit@01ra66it
    Active Exploitation

    【GUARDIANWALL MailSuiteで実悪用済みRCE、CVE-2026-32661】 JVNが、GUARDIANWALL MailSuiteのスタックベースのバッファオーバーフロー脆弱性を緊急扱いで公表しました。対象はオンプレミス版Ver 1.4.00〜2.4.26などで、細工されたリクエストにより任意コード実行につながる可能性があります。 重要なのは、開発者がオンプレミス版での悪用確認を示している点です。メールセキュリティ製品は境界に近い位置で動くことが多く、侵害されるとメール経路、認証情報、内部ネットワークの足場に発展するおそれがあります。 日本のSOCは、対象バージョンの有無、外部到達性、修正パッチ適用状況、脆弱性公表前後の不審プロセス・設定変更・外向き通信を優先確認すべきです。 #サイバーセキュリティ #脆弱性 #JVN #CVE202632661 #GUARDIANWALL #メールセキュリティ #SOC https://jvn.jp/jp/JVN35567473/

    Post summary

    The article reports that developers have confirmed exploitation of a stack‑based buffer overflow in GUARDIANWALL MailSuite, indicating active exploitation in the wild, but it does not provide PoC, exploit code, patches, or debunking information.

    00001423
    3.7K followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    Guardianwall Mailsuite's CVE-2026-32661 is actively exploited, letting hackers execute remote code via buffer overflow. This is worse than usual: it bypasses all EDR. #NerdieNews #CyberSecurity #InfoSec #PatchTuesday https://t.co/R7LG4wOKWL

    Post summary

    The post asserts that CVE-2026-32661 is currently being exploited for remote code execution through a buffer overflow that evades all EDR solutions.

    0001090
    63 followersView on X
  • Cyber Threat Observatory | Alan Turing Institute@TuringCyberObs
    Disclosure

    CVE-2026-32661 (Canon GUARDIANWALL) is a critical stack-based buffer overflow enabling unauthenticated RCE via pop3wallpasswd. Impact is high See full analysis: https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-05-13/TIER_2_CVE-2026-32661.md #CyberSecurity #DPI #DigitalIdentity #EmailSecurity #VulnerabilityManagement

    Post summary

    CVE-2026-32661 is a critical stack‑based buffer overflow in Canon GUARDIANWALL that allows unauthenticated remote code execution via pop3wallpasswd. Detailed analysis is available in the linked report.

    0000077
    44 followersView on X
  • Mr.Rabbit@01ra66it
    Active Exploitation

    【JVN#35567473: GUARDIANWALL MailSuiteにおけるスタックベースのバッファオーバーフローの脆弱性】 JVNは、GUARDIANWALL MailSuiteにおけるスタックベースのバッファオーバーフロー脆弱性 CVE-2026-32661 を緊急として公開しました。CVSS v3基本値は9.8で、Webサービスへの細工リクエストにより任意コード実行につながる可能性があります。 影響を受けるのは、GUARDIANWALL MailSuiteオンプレミス版 Ver 1.4.00からVer 2.4.26まで、および2026年4月30日のメンテナンスより前のGUARDIANWALL Mailセキュリティ・クラウドです。オンプレミス版では悪用が確認されているため、対象組織は即時対応が必要です。 防御側は、パッチ適用、ワークアラウンド、外部到達性の確認を行ってください。あわせて、メールゲートウェイ上の不審プロセス、外向き通信、管理者追加、検疫領域への異常アクセスを確認することが重要です。 #JVN #GUARDIANWALL #CVE202632661 #RCE #メールゲートウェイ #サイバーセキュリティ https://jvn.jp/jp/JVN35567473/

    Post summary

    The post reports a critical stack‑based buffer overflow (CVE‑2026‑32661) in GUARDIANWALL MailSuite, confirming active exploitation of the on‑premise versions and urging immediate patching and mitigation.

    00000308
    3.7K followersView on X

Explore more