Security Advisory

CVE-2026-44128

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-05-08 13:13:46
Last updated 2026-05-18 16:13:51
Assigner NCSC.ch
CVSS score 9.3
State PUBLISHED

Description

SEPPmail Secure Email Gateway before version 15.0.2.1 allows unauthenticated remote code execution in the new GINA UI because an endpoint passes attacker-controlled input from a parameter to Perl's eval.