Mail Gateway Flaws Expose Traffic and Internal Access

SEPPMail is more than a filtering layer here. A compromise can expose protected mail flows and give an attacker a foothold inside the network, so patching this box is not just about closing a web flaw. InfoGuard Labs disclosed seven SEPPMail Secure E-Mail Gateway vulnerabilities at once, covering remote code execution, path traversal, authorization bypass, deserialization, and eval injection. The issues affect the Secure E-Mail Gateway appliance and are fixed across staggered releases from 15.0.2.1 through 15.0.4. The practical problem is blast radius. A vulnerable gateway can reveal arbitrary mailbox traffic and act as an entry point into the internal network, so some appliances remain exposed until the right 15.0.x fix is in place.

Part of the PlainSec briefing for 2026-05-20

Sources