CVE-2026-44126

CRITICAL

SEPPmail Secure Email Gateway - Insecure Deserialization

Title source: manual
STIX 2.1

Description

SEPPmail Secure Email Gateway before version 15.0.4 insecurely deserializes untrusted data, which can be reached from the new GINA UI and may allow unauthenticated remote attackers to execute code via a crafted serialized object.

Scores

CVSS v4 9.2
EPSS 0.0047
EPSS Percentile 36.9%
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-502
Status published
Products (1)
SEPPmail AG/Secure Email Gateway < 15.0.4
Published May 08, 2026
Tracked Since May 08, 2026