Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Seppmail

First CVE: Nov 18, 2022Active for: 4 yearsTotal CVEs: 26
36.9
VTI Score
Medium

Seppmail develops secure email gateway appliances designed to protect enterprise messaging infrastructure through encryption and threat filtering, a role that places the product in a critical position within organizational network perimeters. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and concentrate in input-handling and validation weakness classes including improper input validation, cross-site scripting, certificate validation defects, path traversal, and LDAP injection flaws. These recurring weaknesses reflect the gateway's exposure to untrusted external email streams and its responsibility for parsing, validating, and routing message content across trust boundaries. Defenders operating this class of appliance should prioritize patching cycles and monitor for variants of validation-bypass and injection attacks endemic to message-processing software. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
26
Total CVEs
More Total CVEs than 97% of tracked vendors
4.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 51% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Seppmail over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 18, 2022
3 years ago
Most Recent CVE
Apr 2, 2026
113 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-29139CRITICAL
SEPPmail Secure Email Gateway before version 15.0.3 allows account takeover by abusing GINA account initialization to reset a victim account password.
Apr 2, 20269.835NONO
CVE-2026-29133CRITICAL
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to upload PGP keys with UIDs that do not match their email address.
Apr 2, 20269.133NONO
CVE-2026-2743CRITICAL
Arbitrary File Write via Path Traversal upload to Remote Code Execution in SeppMail User Web Interface. The affected feature is the large file transfer (LFT). This issue affects
Mar 5, 20269.832NONO
CVE-2026-27441CRITICAL
SEPPmail Secure Email Gateway before version 15.0.1 insufficiently neutralizes the PDF encryption password, allowing OS command execution.
Mar 4, 20269.832NONO
CVE-2026-29135HIGH
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to craft a password-tag that bypasses subject sanitization.
Apr 2, 20267.529NONO
CVE-2026-29134HIGH
SEPPmail Secure Email Gateway before version 15.0.3 allows an external user to modify GINA webdomain metadata and bypass per-domain restrictions.
Apr 2, 20267.529NONO
CVE-2026-29131HIGH
SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted email address to read the contents of emails encrypted for other users.
Apr 2, 20267.529NONO
CVE-2026-29143CRITICAL
SEPPmail Secure Email Gateway before version 15.0.3 does not properly authenticate the inner message of S/MIME-encrypted MIME entities, allowing an attacker to control trusted head
Apr 2, 20269.128NONO
CVE-2026-27443HIGH
SEPPmail Secure Email Gateway before version 15.0.1 does not properly sanitize the headers from S/MIME protected MIME entities, allowing an attacker to control trusted headers.
Mar 4, 20267.526NONO
CVE-2026-27442HIGH
The GINA web interface in SEPPmail Secure Email Gateway before version 15.0.1 does not properly check attachment filenames in GINA-encrypted emails, allowing an attacker to access
Mar 4, 20267.526NONO
View all 26 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products26 CVEs
42%
38%
19%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network26 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low26 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None23 (88.5%)
Unknown0 (0.0%)
Required3 (11.5%)
Privileges Required
Low1 (3.8%)
High0 (0.0%)
None25 (96.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (26 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Seppmail.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Seppmail — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Seppmail's Products

View all 2 CNAs →

Top CWEs