seppmail_secure_email_gateway_seg vulnerabilities
CVEs whose affected-version data names the seppmail_secure_email_gateway_seg package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-84832High· 8.6Unsafe deserialization in the REST interface
SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import workflow without adequate validation. An attacker with a privileged API token can execute arbitrary commands with "nobody" priv…
▾ TwilightSEPPmail AG · SEPPmail Secure Email Gateway (SEG)EPSS 0.64%via CVEORG
CVE-2026-84831High· 7.7Mandatory MFA bypass before enrollment
SEPPmail Secure Email Gateway before 15.0.7 creates a fully privileged session before required multi-factor authentication enrollment is completed. An attacker with the password for an MFA-required but unenrolled account can access prote…
▾ TwilightSEPPmail AG · SEPPmail Secure Email Gateway (SEG)EPSS 0.47%via CVEORG