Secure Email Gateway
Vendor:
First CVE: Apr 2, 2026 · Active for under a year
14
Total CVEs
More Total CVEs than 92% of tracked products
14.0
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Secure Email Gateway over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 2, 2026
3 months ago
Most Recent CVE
Apr 2, 2026
117 days ago
CVE Severity & Scoring
Secure Email Gateway14 CVEs
43%
36%
21%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network14 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None13 (92.9%)
Unknown0 (0.0%)
Required1 (7.1%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None14 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-29139CRITICAL SEPPmail Secure Email Gateway before version 15.0.3 allows account takeover by abusing GINA account initialization to reset a victim account password. | Apr 2, 2026 | 9.8 | 35 | NO | NO |
CVE-2026-29133CRITICAL SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to upload PGP keys with UIDs that do not match their email address. | Apr 2, 2026 | 9.1 | 33 | NO | NO |
CVE-2026-29135HIGH SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to craft a password-tag that bypasses subject sanitization. | Apr 2, 2026 | 7.5 | 29 | NO | NO |
CVE-2026-29134HIGH SEPPmail Secure Email Gateway before version 15.0.3 allows an external user to modify GINA webdomain metadata and bypass per-domain restrictions. | Apr 2, 2026 | 7.5 | 29 | NO | NO |
CVE-2026-29131HIGH SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted email address to read the contents of emails encrypted for other users. | Apr 2, 2026 | 7.5 | 29 | NO | NO |
CVE-2026-29143CRITICAL SEPPmail Secure Email Gateway before version 15.0.3 does not properly authenticate the inner message of S/MIME-encrypted MIME entities, allowing an attacker to control trusted head | Apr 2, 2026 | 9.1 | 28 | NO | NO |
CVE-2026-29138HIGH SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted email address to claim another user's PGP signature as their own. | Apr 2, 2026 | 7.5 | 24 | NO | NO |
CVE-2026-29132HIGH SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker with access to a victim's GINA account to bypass a second-password check and read protected emails. | Apr 2, 2026 | 7.5 | 24 | NO | NO |
CVE-2026-29136MEDIUM SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to inject HTML into notification emails about new CA certificates. | Apr 2, 2026 | 6.1 | 21 | NO | NO |
CVE-2026-29144MEDIUM SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge security tags using Unicode lookalike characters. | Apr 2, 2026 | 5.3 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (14 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (14 CVEs).
Media Mentions
Signals from CVEs in this product scope (14 CVEs).
Top CNAs Publishing CVEs For Secure Email Gateway
Top CWEs
Versions
No cataloged versions.