CVE-2026-7864: exploitation status and patch state
CVE-2026-7864 · EPSS 17%
SEPPmail Secure Email Gateway before version 15.0.4 exposes server environment variables through an unauthenticated endpoint in the new GINA UI, allowing remote attackers to obtain sensitive system information.
Is CVE-2026-7864 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at 17%.
Public exploit code: none found in monitored sources.