Browse all 25 CVE security advisories affecting SEPPmail. AI-powered Chinese analysis, POCs, and references for each vulnerability.
SEPPmail is an email security appliance designed to protect organizations from spam, viruses, and phishing through advanced filtering and encryption capabilities. Historically, its software architecture has exhibited significant security flaws, resulting in twenty-four recorded Common Vulnerabilities and Exposures. These vulnerabilities predominantly involve remote code execution, cross-site scripting, and privilege escalation, often stemming from insufficient input validation and improper access controls within the management interface. Notable incidents include critical flaws allowing unauthenticated attackers to execute arbitrary commands or bypass authentication mechanisms, potentially leading to full system compromise. The high volume of disclosed CVEs indicates persistent weaknesses in the product’s development lifecycle and patch management processes. Consequently, administrators are advised to maintain strict version control and apply security updates promptly to mitigate the risk of exploitation by threat actors targeting these known entry points.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-9592 | Sensitive Information Disclosure in HTTP header — SEPPmail Secure Email Gateway & SEPPmail Cloud CWE-598 | - | - | 2026-07-17 |
| CVE-2026-29136 | CA Notification HTML Injection — Secure Email Gateway CWE-79 | 5.4AI | Medium AI | 2026-04-02 |
| CVE-2026-29139 | GINA State Confusion Account Takeover — Secure Email Gateway CWE-288 | 9.8AI | Critical AI | 2026-04-02 |
| CVE-2026-29144 | Unicode Subject Tags — Secure Email Gateway CWE-20 | 5.3AI | Medium AI | 2026-04-02 |
| CVE-2026-29143 | S/MIME Decryption Impersonation — Secure Email Gateway CWE-20 | 8.2AI | High AI | 2026-04-02 |
| CVE-2026-29138 | PGP Decryption Sender LDAP Injection — Secure Email Gateway CWE-90 | 4.3AI | Medium AI | 2026-04-02 |
| CVE-2026-29131 | PGP Decryption Recipient LDAP Injection — Secure Email Gateway CWE-90 | 6.5AI | Medium AI | 2026-04-02 |
| CVE-2026-29142 | Plaintext secure-mail.html — Secure Email Gateway CWE-325 | 7.5AI | High AI | 2026-04-02 |
| CVE-2026-29137 | Long Subject Untagging — Secure Email Gateway CWE-20 | 5.3AI | Medium AI | 2026-04-02 |
| CVE-2026-29141 | Bounded Subject Tag Sanitization — Secure Email Gateway CWE-20 | 5.3AI | Medium AI | 2026-04-02 |
| CVE-2026-29135 | Webmail Password Tag Sanitization Bypass — Secure Email Gateway CWE-20 | 8.2AI | High AI | 2026-04-02 |
| CVE-2026-29134 | GINA Domain Switch — Secure Email Gateway CWE-807 | 5.3AI | Medium AI | 2026-04-02 |
| CVE-2026-29140 | S/MIME Signature Additional Certificate — Secure Email Gateway CWE-295 | 7.5AI | High AI | 2026-04-02 |
| CVE-2026-29133 | UID Regex Bypass — Secure Email Gateway CWE-20 | 9.1AI | Critical AI | 2026-04-02 |
| CVE-2026-29132 | ESWmail-Verify Bypass — Secure Email Gateway CWE-306 | 4.3AI | Medium AI | 2026-04-02 |
| CVE-2026-2743 | SEPPmail User Web Interface Arbitrary File Write to RCE — SeppMail CWE-22 | 8.8 | - | 2026-03-05 |
| CVE-2026-27441 | PDF Password CMDi — Secure Email Gateway CWE-78 | 9.8AI | Critical AI | 2026-03-04 |
| CVE-2026-2748 | S/MIME Certificate Subject Whitespace — Secure Email Gateway CWE-295 | 7.5AI | High AI | 2026-03-04 |
| CVE-2026-27442 | zip_attachments Path Traversal — Secure Email Gateway CWE-22 | 7.5AI | High AI | 2026-03-04 |
| CVE-2026-27445 | PGP Signature Reflection — Secure Email Gateway CWE-347 | 7.5AI | High AI | 2026-03-04 |
| CVE-2026-27444 | Header Email Address Parsing — Secure Email Gateway CWE-436 | 9.1AI | Critical AI | 2026-03-04 |
| CVE-2026-2747 | PGP Mixed Plaintext and Encrypted Content — Secure Email Gateway CWE-200 | 5.3AI | Medium AI | 2026-03-04 |
| CVE-2026-27443 | S/MIME Decryption Tag Sanitization Bypass — Secure Email Gateway CWE-20 | 7.5AI | High AI | 2026-03-04 |
| CVE-2026-2746 | Missing PGP Signature Tag — Secure Email Gateway CWE-347 | 5.3AI | Medium AI | 2026-03-04 |
| CVE-2022-41871 | SEPPmail 安全漏洞 — SEPPmail CWE-78 | 6.0 | Medium | 2025-04-28 |
This page lists every published CVE security advisory associated with SEPPmail. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.