CVE-2026-41113Disclosure

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

sagredo qmail before 2026.04.07 allows tls_quit remote code execution because of popen in notlshosts_auto in qmail-remote.c.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-17); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-17: 2Mentions · 2026-04-19: 1Technical Details · 2026-04-17: 2Technical Details · 2026-04-19: 104-1704-19
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-172
Disclosure2
2026-04-191
Disclosure1
Full discourse3 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-41113: sagredo fork of qmail: RCE https://www.openwall.com/lists/oss-security/2026/04/18/5 via popen() in feature called notlshosts_auto that was added in October 2024

    Post summary

    The text announces CVE‑2026‑41113 affecting the sagredo qmail fork, noting an RCE through popen() in the notlshosts_auto feature added in October 2024, without providing PoC or exploitation evidence.

    01030454
    4.7K followersView on X
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Disclosure

    🛡️ CVE‑2026‑41113 – qmail TLS quit RCE (High): In sagredo qmail before 2026.04.07, a popen call in notlshosts_auto within qmail-remote.c can be reached through tls_quit, enabling remote code execution against mail transport infrastructure. CVSS high, updated today in Tenable’s newest CVE feed and affecting a core mail stack component used in production systems. https://www.tenable.com/cve/CVE-2026-41113 #CVE202641113 #Qmail #EmailSecurity #RCE #ThreatIntel

    Post summary

    CVE‑2026‑41113 is a high‑severity remote code execution vulnerability in qmail’s TLS quit handling, detailed with technical specifics but no PoC, exploit code, or indications of active exploitation.

    0001065
    853 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41113 sagredo qmail before 2026.04.07 allows tls_quit remote code execution because of popen in notlshosts_auto in qmail-remote.c. https://www.cve.org/CVERecord?id=CVE-2026-41113

    Post summary

    The post announces CVE-2026-41113, detailing a remote code execution vulnerability in qmail caused by a popen call during TLS quit.

    0000075
    57.2K followersView on X

Explore more