---
schema: 1
kind: vulnerability
title: >
  CVE-2026-44128 et al. — SEPPmail Secure Email Gateway: CVSS 9.3 unauthenticated RCE and five
  additional CVEs
headline: >
  CVE-2026-44128 et al. — SEPPmail Secure Email Gateway: CVSS 9.3 unauthenticated RCE and five
  additional CVEs
summary: >
  SEPPmail (Swiss secure email gateway) — NCSC-CH advisory 12551 covers CVSS 9.3 CRITICAL
  unauthenticated RCE via exposed test endpoints (CVE-2026-44128) plus two additional CRITICAL and
  two HIGH CVEs. Swiss/DACH public-sector and healthcare deployments should patch to version
  15.0.4 immediately. Full technical breakdown in § 6.
discovered_at: "2026-05-09T05:00:05Z"
updated_at: "2026-05-20T05:00:12Z"
event_date: 2026-05-08
run_id: 2026-05-09-migrated
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - pre-auth
  - rce
  - auth-bypass
  - patch-available
  - path-traversal
regions:
  - switzerland
  - dach
  - europe
sectors:
  - public-sector
  - healthcare
  - finance
entities: []
techniques: []
affected_products: []
cves:
  - id: CVE-2026-44128
    cvss: "9.3"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
  - id: CVE-2026-44125
    cvss: "9.3"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
  - id: CVE-2026-44126
    cvss: "9.2"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
  - id: CVE-2026-44127
    cvss: "8.8"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
  - id: CVE-2026-44129
    cvss: "8.3"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
  - id: CVE-2026-7864
    cvss: "6.9"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
  - id: CVE-2026-2743
    cvss: "10.0"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
sources:
  - url: "https://security-hub.ncsc.admin.ch/api/posts/12551/details"
    publisher: "NCSC-CH Security Hub post 12551, 2026-05-08"
    role: primary
  - url: "https://downloads.seppmail.com/extrelnotes/150/ERN15.0.html#security"
    publisher: SEPPmail release notes v15.0
    role: corroborating
  - url: "https://labs.infoguard.ch/posts/seppmail_secure_e-mail_gateway_rce_vulnerabilities_cve-2026-2743_cve-2026-7864_cve-2026-44127_cve-2026-44128/"
    publisher: "InfoGuard Labs technical analysis, 2026-05-18"
    role: primary
  - url: "https://thehackernews.com/2026/05/seppmail-secure-e-mail-gateway.html"
    publisher: "The Hacker News, 2026-05-19"
    role: corroborating
  - url: "https://cybersecuritynews.com/seppmail-gateway-flaws/"
    publisher: "CybersecurityNews, 2026-05-19"
    role: corroborating
closed_sources: []
evidence: []
verification: single-source-national-cert
sourcing_note: null
confidence: high
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification: null
watchlist_hit: false
actions:
  - "**Apply SEPPmail v15.0.4 to any DACH-region deployment still on an earlier build.** CVE-2026-2743 (CVSS 10.0, pre-auth path-traversal-to-RCE via LFT) is also addressed by v15.0.4 — but if you delayed updating on the assumption disabled LFT limited exposure, re-evaluate now (InfoGuard's scan finds the majority of customer instances have LFT enabled) ([InfoGuard Labs, 2026-05-18](https://labs.infoguard.ch/posts/seppmail_secure_e-mail_gateway_rce_vulnerabilities_cve-2026-2743_cve-2026-7864_cve-2026-44127_cve-2026-44128/))."
updates:
  - at: "2026-05-20T05:00:12Z"
    run_id: 2026-05-20-a0f7b07f
    type: update
    summary: >
      UPDATE (originally covered 2026-05-09 deep dive on CVE-2026-44128 cluster): InfoGuard Labs — the
      Baar-based Swiss security firm that performed the original SEPPmail review — published its full
      technical write-up on 2026-05-18.
    fields:
      - actions
      - cves
      - regions
      - sectors
      - sources
      - tags
      - body
    merged_from: 2026-05-20/seppmail-secure-e-mail-gateway-infoguard-labs-full-technical
migrated_from: briefs/2026-05-09.md
---

NCSC-CH published advisory post 12551 on 2026-05-08 covering six CVEs in SEPPmail Secure Email Gateway patched in version 15.0.4 (patch 15.0.4.1). SEPPmail is a Swiss company (Steinach SG) whose gateway handles S/MIME, PGP, and TLS email encryption for Swiss federal agencies, cantonal administrations, healthcare providers, and DACH-region enterprises. Vulnerability summary: **CVE-2026-44128** (CVSS 9.3 CRITICAL) — unauthenticated RCE via test/development HTTP endpoints left active in the GINAv2 component; **CVE-2026-44125** (CVSS 9.3 CRITICAL) — missing authorisation in GINAv2 enabling unauthenticated administrative access and file manipulation; **CVE-2026-44126** (CVSS 9.2 CRITICAL) — insecure deserialisation enabling full gateway takeover; **CVE-2026-44127** (CVSS 8.8 HIGH) — local file inclusion and arbitrary file deletion; **CVE-2026-44129** (CVSS 8.3 HIGH) — server-side template injection; **CVE-2026-7864** (CVSS 6.9 MEDIUM). No exploitation has been confirmed; all critical paths are pre-authentication ([NCSC-CH advisory 12551, 2026-05-08](https://security-hub.ncsc.admin.ch/api/posts/12551/details) · [SEPPmail release notes v15.0](https://downloads.seppmail.com/extrelnotes/150/ERN15.0.html#security)).

## Update — 2026-05-20T05:00:12Z

[InfoGuard Labs](https://labs.infoguard.ch/posts/seppmail_secure_e-mail_gateway_rce_vulnerabilities_cve-2026-2743_cve-2026-7864_cve-2026-44127_cve-2026-44128/) — the Baar-based Swiss security firm that performed the original SEPPmail review — published its full technical write-up on 2026-05-18. The principal new finding is **CVE-2026-2743 (CVSS 10.0)**: a pre-authenticated path traversal in SEPPmail's **Large File Transfer (LFT)** component (`/v1/file.app` endpoint, `handle_request` function) that passes a JSON-supplied filename through `WebMailMessage::store_attachments` without sanitisation. The attacker writes arbitrary files as the `nobody` user; because `nobody` has unusual write access to `/etc/syslog.conf`, an attacker can overwrite it with a piped Perl reverse-shell one-liner and trigger a `newsyslog` rotation (15-minute cron sending `SIGHUP` to syslogd) to obtain unauthenticated RCE.

CVE-2026-2743 only affects instances with the **LFT license** enabled (exposure is detectable: `/v1/file.app` returns 404 if LFT is not provisioned). InfoGuard's Censys-driven scan suggests the majority of customer instances do have LFT enabled. The 2026-05-09 deep dive covered CVE-2026-44128 / 44125 / 44126 / 44127 / 44129 / 7864, all patched in v15.0.4; **CVE-2026-2743 is also addressed by v15.0.4** but defenders that delayed the v15.0.4 update on the assumption their LFT-disabled posture limited exposure should re-evaluate: any host running an earlier build is now a pre-auth-RCE candidate independent of the GINA V2 path. InfoGuard notes: ["The chain allows for a complete takeover of the SEPPmail appliance. Attackers can read all mail traffic and persist indefinitely on the gateway. On these virtual appliances the Blue Teams have usually no visibility."](https://labs.infoguard.ch/posts/seppmail_secure_e-mail_gateway_rce_vulnerabilities_cve-2026-2743_cve-2026-7864_cve-2026-44127_cve-2026-44128/) Apply v15.0.4 to all Swiss / DACH SEPPmail appliances immediately if any remain on an earlier build; monitor `/v1/file.app` POST requests with `../` sequences in the JSON body; alert on unexpected Perl process trees spawned by `syslogd`.
