SEPPmail AG has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 8.6 (high). Most affected products: SEPPmail Secure Email Gateway (SEG) (2), Secure Email Gateway (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.6
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
Products
- SEPPmail Secure Email Gateway (SEG) 2
- Secure Email Gateway 1
SEPPmail AG vulnerabilities
CVEs affecting SEPPmail AG, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-84830High· 8.6OS command injection in privileged configuration handling
SEPPmail Secure Email Gateway before 15.0.7 contains a command injection vulnerability that allows authenticated administrators to execute commands with elevated privileges.
CVE-2026-84832High· 8.6Unsafe deserialization in the REST interface
SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import workflow without adequate validation. An attacker with a privileged API token can execute arbitrary commands with "nobody" priv…
CVE-2026-84831High· 7.7Mandatory MFA bypass before enrollment
SEPPmail Secure Email Gateway before 15.0.7 creates a fully privileged session before required multi-factor authentication enrollment is completed. An attacker with the password for an MFA-required but unenrolled account can access prote…