CVE-2026-6350 is a critical stack-based buffer overflow vulnerability affecting MailGates and MailAudit products developed by Openfind, permitting unauthenticated remote attackers to achieve arbitrary code execution by compromising the program's execution flow. The vulnerability carries a CVSS score of 9.8 (Critical) with a network-based attack vector requiring no authentication, user interaction, or elevated privileges, resulting in complete compromise of confidentiality, integrity, and availability. Current exploitation activity remains limited, as evidenced by the vulnerability's absence from the Known Exploited Vulnerabilities catalog and relatively low EPSS probability score of 0.000770000, indicating minimal community attention and active exploitation at this time. Organizations operating Openfind mail gateway or audit products should prioritize patching efforts given the critical severity rating and the ease with which remote unauthenticated attackers could achieve system compromise.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Openfind | MailAudit | >= 5.0, < 5.2.10.099, >= 6.0, < 6.1.10.054CNA affecteddefault unaffected | |
| Openfind | MailGates | >= 5.0, < 5.2.10.099, >= 6.0, < 6.1.10.054CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.