CVE-2026-2743: exploitation status and patch state
CVE-2026-2743 · CVSS 9.8 CRITICAL · EPSS 1%
Arbitrary File Write via Path Traversal upload to Remote Code Execution in SeppMail User Web Interface. The affected feature is the large file transfer (LFT).
This issue affects SeppMail: 15.0.2.1 and before
Is CVE-2026-2743 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at 1%.
Public exploit code: none found in monitored sources.