seppmail CVE Vulnerabilities & Metrics

Focus on seppmail vulnerabilities and metrics.

Last updated: 08 Mar 2026, 23:25 UTC

About seppmail Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with seppmail. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total seppmail CVEs: 11
Earliest CVE date: 18 Nov 2022, 23:15 UTC
Latest CVE date: 04 Mar 2026, 09:15 UTC

Latest CVE reference: CVE-2026-2748

Rolling Stats

30-day Count (Rolling): 8
365-day Count (Rolling): 9

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical seppmail CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 0.0

Max CVSS: 0

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 11
4.0-6.9 0
7.0-8.9 0
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS seppmail CVEs

These are the five CVEs with the highest CVSS scores for seppmail, sorted by severity first and recency.

All CVEs for seppmail

CVE-2026-2748 seppmail vulnerability CVSS: 0 04 Mar 2026, 09:15 UTC

SEPPmail Secure Email Gateway before version 15.0.1 improperly validates S/MIME certificates issued for email addresses containing whitespaces, allowing signature spoofing.

CVE-2026-2747 seppmail vulnerability CVSS: 0 04 Mar 2026, 09:15 UTC

SEPPmail Secure Email Gateway before version 15.0.1 decrypts inline PGP messages without isolating them from surrounding unencrypted content, allowing exposure of sensitive information to an unauthorized actor.

CVE-2026-2746 seppmail vulnerability CVSS: 0 04 Mar 2026, 09:15 UTC

SEPPmail Secure Email Gateway before version 15.0.1 does not properly communicate PGP signature verification results, leaving users unable to detect forged emails.

CVE-2026-27445 seppmail vulnerability CVSS: 0 04 Mar 2026, 09:15 UTC

SEPPmail Secure Email Gateway before version 15.0.1 does not properly verify that a PGP signature was generated by the expected key, allowing signature spoofing.

CVE-2026-27444 seppmail vulnerability CVSS: 0 04 Mar 2026, 09:15 UTC

SEPPmail Secure Email Gateway before version 15.0.1 incorrectly interprets email addresses in the email headers, causing an interpretation conflict with other mail infrastructure that allows an attacker to fake the source of the email or decrypt it.

CVE-2026-27443 seppmail vulnerability CVSS: 0 04 Mar 2026, 09:15 UTC

SEPPmail Secure Email Gateway before version 15.0.1 does not properly sanitize the headers from S/MIME protected MIME entities, allowing an attacker to control trusted headers.

CVE-2026-27442 seppmail vulnerability CVSS: 0 04 Mar 2026, 09:15 UTC

The GINA web interface in SEPPmail Secure Email Gateway before version 15.0.1 does not properly check attachment filenames in GINA-encrypted emails, allowing an attacker to access files on the gateway.

CVE-2026-27441 seppmail vulnerability CVSS: 0 04 Mar 2026, 09:15 UTC

SEPPmail Secure Email Gateway before version 15.0.1 insufficiently neutralizes the PDF encryption password, allowing OS command execution.

CVE-2022-41871 seppmail vulnerability CVSS: 0 28 Apr 2025, 16:15 UTC

SEPPmail through 12.1.17 allows command injection within the Admin Portal. An authenticated attacker is able to execute arbitrary code in the context of the user root.

CVE-2021-31740 seppmail vulnerability CVSS: 0 30 Nov 2022, 15:15 UTC

SEPPMail's web frontend, user input is not embedded correctly in the web page and therefore leads to cross-site scripting vulnerabilities (XSS).

CVE-2021-31739 seppmail vulnerability CVSS: 0 18 Nov 2022, 23:15 UTC

The SEPPmail solution is vulnerable to a Cross-Site Scripting vulnerability (XSS), because user input is not correctly encoded in HTML attributes when returned by the server.SEPPmail 11.1.10 allows XSS via a recipient address.