VulnSea

cyrus has 5 CVEs on record. 5 were published in the last 90 days. The busiest recent month was September 2026 with 5. The median CVSS is 3.5 (low). None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
3.5
Publish → KEV
Last 90 days
5 prev 0

Products

  • imap 5
5
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

cyrus vulnerabilities

CVEs affecting cyrus, newest first. Open any entry for full detail, references, and exploit status.

5 CVEsRSS

CVE-2026-61915Medium· 4.2
1w ago

An issue was discovered in Cyrus IMAP before 3.12.4

An issue was discovered in Cyrus IMAP before 3.12.4. There is a VPATCH BYPARAM double-free. An authenticated calendar user could crash a Cyrus CalDAV worker with a PATCH containing PATCH-ACTION="BYPARAM@..." against a resource with two o…

Sunlitcyrus · imapEPSS 0.26%via NVD
CVE-2026-61909Low· 3.5
1w ago

An issue was discovered in Cyrus IMAP before 3.12.4

An issue was discovered in Cyrus IMAP before 3.12.4. CalDAV/CardDAV multiget bypasses a per-href ACL. An authenticated DAV user with some shared access to another user's calendar or address book could read even unshared events or contact…

Sunlitcyrus · imapEPSS 0.20%via NVD
CVE-2026-61910Low· 3.5
1w ago

An issue was discovered in Cyrus IMAP before 3.12.4

An issue was discovered in Cyrus IMAP before 3.12.4. Mailbox/set let a sharee change a special-use role on shared mailboxes. An authenticated user with maySetKeywords on another user's mailbox could change that mailbox's specialuse annot…

Sunlitcyrus · imapEPSS 0.19%via NVD
CVE-2026-61911Medium· 4.3
1w ago

An issue was discovered in Cyrus IMAP before 3.12.4

An issue was discovered in Cyrus IMAP before 3.12.4. There is a Sieve mailbox existence oracle. An authenticated user could install a Sieve script that probed whether another user's private mailbox existed, or read the value of shared ma…

Sunlitcyrus · imapEPSS 0.22%via NVD
CVE-2026-61908Low· 3.1
1w ago

An issue was discovered in Cyrus IMAP before 3.12.4

An issue was discovered in Cyrus IMAP before 3.12.4. A JMAP email-header blob ID can reference an out-of-bounds index. An authenticated user could attempt to download a crafted JMAP blob ID of the form H<emailid>-<index>, which could rea…

Sunlitcyrus · imapEPSS 0.22%via NVD
cyrus vulnerabilities (CVEs) · VulnSea