Seppmail develops secure email gateway appliances designed to protect enterprise messaging infrastructure through encryption and threat filtering, a role that places the product in a critical position within organizational network perimeters. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and concentrate in input-handling and validation weakness classes including improper input validation, cross-site scripting, certificate validation defects, path traversal, and LDAP injection flaws. These recurring weaknesses reflect the gateway's exposure to untrusted external email streams and its responsibility for parsing, validating, and routing message content across trust boundaries. Defenders operating this class of appliance should prioritize patching cycles and monitor for variants of validation-bypass and injection attacks endemic to message-processing software. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Seppmail over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-29139CRITICAL SEPPmail Secure Email Gateway before version 15.0.3 allows account takeover by abusing GINA account initialization to reset a victim account password. | Apr 2, 2026 | 9.8 | 35 | NO | NO |
CVE-2026-29133CRITICAL SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to upload PGP keys with UIDs that do not match their email address. | Apr 2, 2026 | 9.1 | 33 | NO | NO |
CVE-2026-2743CRITICAL Arbitrary File Write via Path Traversal upload to Remote Code Execution in SeppMail User Web Interface. The affected feature is the large file transfer (LFT).
This issue affects | Mar 5, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-27441CRITICAL SEPPmail Secure Email Gateway before version 15.0.1 insufficiently neutralizes the PDF encryption password, allowing OS command execution. | Mar 4, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-29135HIGH SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to craft a password-tag that bypasses subject sanitization. | Apr 2, 2026 | 7.5 | 29 | NO | NO |
CVE-2026-29134HIGH SEPPmail Secure Email Gateway before version 15.0.3 allows an external user to modify GINA webdomain metadata and bypass per-domain restrictions. | Apr 2, 2026 | 7.5 | 29 | NO | NO |
CVE-2026-29131HIGH SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted email address to read the contents of emails encrypted for other users. | Apr 2, 2026 | 7.5 | 29 | NO | NO |
CVE-2026-29143CRITICAL SEPPmail Secure Email Gateway before version 15.0.3 does not properly authenticate the inner message of S/MIME-encrypted MIME entities, allowing an attacker to control trusted head | Apr 2, 2026 | 9.1 | 28 | NO | NO |
CVE-2026-27443HIGH SEPPmail Secure Email Gateway before version 15.0.1 does not properly sanitize the headers from S/MIME protected MIME entities, allowing an attacker to control trusted headers. | Mar 4, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-27442HIGH The GINA web interface in SEPPmail Secure Email Gateway before version 15.0.1 does not properly check attachment filenames in GINA-encrypted emails, allowing an attacker to access | Mar 4, 2026 | 7.5 | 26 | NO | NO |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Seppmail.
Media articles that mention a CVE ID that affects a product developed by Seppmail — matched by CVE ID, not by vendor name.