CTIPilot

SEPPmail GINAv2, insecure deserialisation via session cookie → RCE (CVSS 9.2)

cve · CVE-2026-44126 single-source-national-cert

Coverage timeline
1
first 2026-05-09 → last 2026-05-10
Peak priority
high
1 high
Sources cited
5
5 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
6
see Co-occurring entities below
ATT&CK techniques
0
no mapped behavior yet

Story timeline

  1. 2026-05-09CVE-2026-44128 et al. SEPPmail Secure Email Gateway: CVSS 9.3 unauthenticated RCE and five additional CVEs
    trending-vulnerabilities

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • cybersecuritynews.com1 (20%)
  • downloads.seppmail.com1 (20%)
  • labs.infoguard.ch1 (20%)
  • security-hub.ncsc.admin.ch1 (20%)
  • thehackernews.com1 (20%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about SEPPmail GINAv2, insecure deserialisation via session cookie → RCE (CVSS 9.2) (1)

2026-05-09 · view entry permalink →

CVE-2026-44128 et al. SEPPmail Secure Email Gateway: CVSS 9.3 unauthenticated RCE and five additional CVEs

NCSC-CH published advisory post 12551 on 2026-05-08 covering six CVEs in SEPPmail Secure Email Gateway patched in version 15.0.4 (patch 15.0.4.1). SEPPmail is a Swiss company (Steinach SG) whose gateway handles S/MIME, PGP, and TLS email encryption for Swiss federal agencies, cantonal administrations, healthcare providers, and DACH-region enterprises. Vulnerability summary: CVE-2026-44128 (CVSS 9.3 CRITICAL), unauthenticated RCE via test/development HTTP endpoints left active in the GINAv2 component; CVE-2026-44125 (CVSS 9.3 CRITICAL), missing authorisation in GINAv2 enabling unauthenticated administrative access and file manipulation; CVE-2026-44126 (CVSS 9.2 CRITICAL), insecure deserialisation enabling full gateway takeover; CVE-2026-44127 (CVSS 8.8 HIGH), local file inclusion and arbitrary file deletion; CVE-2026-44129 (CVSS 8.3 HIGH), server-side template injection; CVE-2026-7864 (CVSS 6.9 MEDIUM). No exploitation has been confirmed; all critical paths are pre-authentication (NCSC-CH advisory 12551, 2026-05-08 · SEPPmail release notes v15.0).

Updaterun 2026-05-20-a0f7b07factionscvesregionssectorssourcestagsbody

InfoGuard Labs (the Baar-based Swiss security firm that performed the original SEPPmail review) published its full technical write-up on 2026-05-18. The principal new finding is CVE-2026-2743 (CVSS 10.0): a pre-authenticated path traversal in SEPPmail's Large File Transfer (LFT) component (/v1/file.app endpoint, handle_request function) that passes a JSON-supplied filename through WebMailMessage::store_attachments without sanitisation. The attacker writes arbitrary files as the nobody user; because nobody has unusual write access to /etc/syslog.conf, an attacker can overwrite it with a piped Perl reverse-shell one-liner and trigger a newsyslog rotation (15-minute cron sending SIGHUP to syslogd) to obtain unauthenticated RCE.

CVE-2026-2743 only affects instances with the LFT license enabled (exposure is detectable: /v1/file.app returns 404 if LFT is not provisioned). InfoGuard's Censys-driven scan suggests the majority of customer instances do have LFT enabled. The 2026-05-09 deep dive covered CVE-2026-44128 / 44125 / 44126 / 44127 / 44129 / 7864, all patched in v15.0.4; CVE-2026-2743 is also addressed by v15.0.4 but defenders that delayed the v15.0.4 update on the assumption their LFT-disabled posture limited exposure should re-evaluate: any host running an earlier build is now a pre-auth-RCE candidate independent of the GINA V2 path. InfoGuard notes: "The chain allows for a complete takeover of the SEPPmail appliance. Attackers can read all mail traffic and persist indefinitely on the gateway. On these virtual appliances the Blue Teams have usually no visibility." Apply v15.0.4 to all Swiss / DACH SEPPmail appliances immediately if any remain on an earlier build; monitor /v1/file.app POST requests with ../ sequences in the JSON body; alert on unexpected Perl process trees spawned by syslogd.

vulnerability09 May 05:00Zsingle-source · national CERTOpen finding ↗