Vulnerabilities · 118 days ago

Mail Gateway Flaws Expose Traffic and Internal Access

SEPPMail is more than a filtering layer here. A compromise can expose protected mail flows and give an attacker a foothold inside the network, so patching this box is not just about closing a web flaw.

InfoGuard Labs disclosed seven SEPPMail Secure E-Mail Gateway vulnerabilities at once, covering remote code execution, path traversal, authorization bypass, deserialization, and eval injection. The issues affect the Secure E-Mail Gateway appliance and are fixed across staggered releases from 15.0.2.1 through 15.0.4.

The practical problem is blast radius. A vulnerable gateway can reveal arbitrary mailbox traffic and act as an entry point into the internal network, so some appliances remain exposed until the right 15.0.x fix is in place.

CVEs in this update

7 CVEs

1 critical · 0 high · 0 medium · 0 low

0 in CISA KEV · 2 with EPSS above 1%

Highest severity: CVE-2026-2743 · 9.8 CRITICAL

Highest EPSS: CVE-2026-7864 · 17%

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-05-20

Editions

Related stories