CVE-2026-6350Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

MailGates/MailAudit developed by Openfind has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers to control the program's execution flow and execute arbitrary code.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • 5 total mentions across 1 day

Deep dive

Activity timeline5 mentions / 1d
01345Mentions · 2026-04-16: 5Patch / Workaround · 2026-04-16: 2Technical Details · 2026-04-16: 504-16
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets4 URLs
Full discourse5 posts
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Disclosure

    ✉️ CVE‑2026‑6350 – MailGates/MailAudit pre‑auth RCE (Critical): In Openfind MailGates/MailAudit 5.x/6.x, a stack‑based buffer overflow in the mail gateway stack allows unauthenticated remote attackers to take control of execution flow and run arbitrary code on the appliance, directly compromising the email security gateway. CVSS 9.8 (v3.1), fixed in MailGates/MailAudit 6.1.10.054 / 5.2.10.099 and later. https://nvd.nist.gov/vuln/detail/CVE-2026-6350 #CVE20266350 #MailGates #MailAudit #RCE #EmailSecurity #ThreatIntel

    Post summary

    The post announces CVE‑2026‑6350 as a critical pre‑authentication RCE caused by a stack‑based buffer overflow in Openfind MailGates/MailAudit, provides its CVSS score, and lists the patched versions for remediation.

    2001044
    855 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-6350 — CVSS 9.8/10 ██████████ MailGates/MailAudit developed by Openfind has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/mkSxUdqdlc

    Post summary

    The tweet highlights a critical stack-based buffer overflow (CVE-2026-6350) in Openfind's MailGates/MailAudit product and urges users to apply the available patch.

    1000058
    23 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6350 Stack-Based Buffer Overflow in Openfind MailGates/MailAudit Enables Remote Code Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6350

    Post summary

    The post discloses a stack‑based buffer overflow vulnerability (CVE‑2026‑6350) in Openfind MailGates/MailAudit that allows remote code execution, providing only basic CVE details and a link to an external database.

    0000067
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6350 MailGates/MailAudit developed by Openfind has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers to control the program's execution … https://www.cve.org/CVERecord?id=CVE-2026-6350

    Post summary

    The post discloses a stack-based buffer overflow in MailGates/MailAudit that lets unauthenticated remote attackers control execution.

    00000277
    57.2K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-6350: Openfind|MailGates/MailAudit - St... Unauthenticated RCE via stack smashing on enterprise mail gateways - perfect for lateral movement once you're inside the... https://zerodaysignal.com/vulnerability/CVE-2026-6350 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2026-6350 as an unauthenticated RCE via stack smashing on Openfind MailGates/MailAudit, with no evidence of active exploitation, PoC, or patch information.

    0000062
    218 followersView on X

Explore more