PatchSiren

Progressive Robot Ltd CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Progressive Robot Ltd CVE published 2026-10-08

CVE-2026-107584

CVE-2026-107584 debrief based on CVE Program and NVD records. The vulnerability in hMailServer allows an attacker to disable DANE for a DNSSEC-signed recipient domain, potentially leading to eavesdropping and tampering with email content. Mail server administrators and security teams should assess exposure and prioritize remediation. The CVE record and NVD detail page provide information on the vulnerabil [truncated]

MEDIUM Progressive Robot Ltd CVE published 2026-10-08

CVE-2026-107583

A vulnerability in Progressive Robot hMailServer 6.3.2 through 6.3.5 allows a remote unauthenticated attacker to cause denial-of-service (DoS) by sending a specially crafted message. The inefficient algorithmic complexity in the webmail's message view of the REST API can lead to one of the listener's four worker threads being busy for minutes and building a document of gigabytes, making the webmail, admin [truncated]

MEDIUM Progressive Robot Ltd CVE published 2026-10-08

CVE-2026-107587

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-10-08T11:49:01.081Z and has not been modified since then. The vulnerability is related to improper certificate validation in hMailServer, which allows a remote unauthenticated attacker to encrypt S/MIME mail using the victim's certificate. This issue affects hMailServer versions 6.3.2 through 6.3.5. De [truncated]

MEDIUM Progressive Robot Ltd CVE published 2026-10-08

CVE-2026-107582

A vulnerability in Progressive Robot hMailServer allows remote unauthenticated attackers to cause denial-of-service conditions by sending specially crafted messages, impacting webmail, administration console, and REST API availability. The vulnerability is caused by inefficient algorithmic complexity in the REST API and IMAP PREVIEW response of hMailServer. Defenders should verify exposure and apply patch [truncated]

MEDIUM Progressive Robot Ltd CVE published 2026-10-08

CVE-2026-107581

PatchSiren debrief for CVE-2026-107581: Inefficient Algorithmic Complexity in hMailServer. The CVE record was published on 2026-10-08T11:47:16.084Z and has not been modified since then. This vulnerability affects hMailServer versions 6.0.0 through 6.3.5, particularly in its IMAP command handling, which can lead to memory issues. Defenders should assess exposure and potential impact, focusing on IMAP comma [truncated]

MEDIUM Progressive Robot Ltd CVE published 2026-10-08

CVE-2026-107580

A vulnerability in hMailServer allows remote unauthenticated attackers to cause denial-of-service (DoS) by sending specially crafted messages that lead to inefficient algorithmic complexity. This issue affects hMailServer versions 6.0.0 through 6.3.5. The vulnerability is caused by inefficient algorithmic complexity in the decoding of message header fields, which can be exploited by sending messages with [truncated]

HIGH Progressive Robot Ltd CVE published 2026-10-08

CVE-2026-107579

A vulnerability in hMailServer allows remote unauthenticated attackers to cause a denial of service by sending specially crafted messages, which can keep delivery threads busy for an extended period. This issue affects hMailServer versions 6.3.4 and 6.3.5. The vulnerability is caused by inefficient algorithmic complexity in the bounce and complaint processing. An attacker can exploit this by sending messa [truncated]

MEDIUM Progressive Robot Ltd CVE published 2026-10-08

CVE-2026-107578

A local attacker with low-privilege service account access can escalate privileges in Progressive Robot hMailServer 6.3.4 and 6.3.5 due to improper link resolution and external control of file paths in administrative command-line operations. This vulnerability allows an attacker to gain elevated privileges, potentially leading to significant impact on the system. Defenders should assess exposure and prior [truncated]

HIGH Progressive Robot Ltd CVE published 2026-10-08

CVE-2026-107576

A vulnerability in hMailServer allows remote unauthenticated attackers to cause denial-of-service conditions by sending specially crafted messages, taking advantage of inefficient algorithmic complexity in DKIM and ARC signature verification. This issue affects hMailServer versions 6.0.0 through 6.3.5 and involves inefficient processing of DKIM and ARC signatures, which can lead to prolonged service unava [truncated]

HIGH Progressive Robot Ltd CVE published 2026-10-08

CVE-2026-107577

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-10-08T11:46:51.086Z and has not been modified since then. The vulnerability affects hMailServer versions 6.0.0 through 6.3.5 and allows a remote unauthenticated attacker to make mail services unavailable by sending a message with a specific MIME header parameter. This can lead to denial of service (DoS [truncated]

MEDIUM Progressive Robot Ltd CVE published 2026-10-08

CVE-2026-107575

A vulnerability in hMailServer allows remote attackers to cause a denial of service by publishing a crafted SPF record that consumes worker-thread time. The issue arises from inefficient algorithmic complexity in the SPF macro expansion of hMailServer 6.3.4 and 6.3.5. An attacker can publish a crafted SPF record to consume worker-thread time, leading to a denial of service. System administrators and secur [truncated]

MEDIUM Progressive Robot Ltd CVE published 2026-10-08

CVE-2026-107572

PatchSiren debrief for CVE-2026-107572: Inefficient Regular Expression Complexity in hMailServer allows an authenticated account holder to make mail services unavailable with their own filter, impacting delivery for the whole server. The vulnerability affects hMailServer versions 6.2.24 through 6.3.5 and involves inefficient Sieve filter evaluation. Defenders should assess exposure and prioritize mitigati [truncated]

HIGH Progressive Robot Ltd CVE published 2026-10-08

CVE-2026-107573

CVE-2026-107573: Incorrect Default Permissions in hMailServer allows local authenticated users to read mail server data due to inherited permissions from the installation folder. The vulnerability exists in the Windows installer of Progressive Robot hMailServer 6.0.0 through 6.3.5, where the installer creates folders and configuration files with permissions that allow local authenticated users to read sen [truncated]

HIGH Progressive Robot Ltd CVE published 2026-10-08

CVE-2026-107574

A remote attacker can exploit inefficient algorithmic complexity in the JSON reader of Progressive Robot hMailServer, causing the mail services to become unavailable. This can be achieved by sending a crafted TLS-RPT report to a hosted domain's published report mailbox or through the webmail's REST routes. The attack requires no authentication and can impact mail delivery for over an hour per report.

MEDIUM Progressive Robot Ltd CVE published 2026-10-08

CVE-2026-103011

A heap-based buffer overflow vulnerability exists in the legacy Blowfish encryption routine of Progressive Robot hMailServer versions 6.0.0 through 6.3.5. An authenticated mailbox user can cause a denial of service (service crash) and potentially other unspecified impacts. This vulnerability can be exploited remotely by adding a fetch account with a password of 129 to 247 characters long and not a multipl [truncated]

HIGH Progressive Robot Ltd CVE published 2026-10-08

CVE-2026-103010

A heap-based buffer overflow vulnerability exists in the legacy Blowfish decryption routine of Progressive Robot hMailServer versions 6.0.0 through 6.3.3 on Windows. This allows a local interactive user with no hMailServer credentials to potentially cause a denial of service (service crash) and possibly execute code with the privileges of the service account, which runs as LocalSystem by default.

HIGH Progressive Robot Ltd CVE published 2026-10-08

CVE-2026-103647

A cross-site scripting vulnerability exists in the webmail of Progressive Robot hMailServer versions 6.3.2 through 6.3.5. An attacker can send a user an encrypted message that, when decrypted and opened as an attachment in a new tab, can run script in the webmail's origin with that user's session, potentially allowing the script to read the mailbox, send mail, and change the account through the REST API.

HIGH Progressive Robot Ltd CVE published 2026-10-08

CVE-2026-103649

The Linux builds of Progressive Robot hMailServer 6.3.0 through 6.3.5 are vulnerable to a denial-of-service attack due to missing network timeouts. A remote attacker can hold server threads indefinitely, stopping outbound mail delivery. Defenders responsible for Linux-based hMailServer instances, especially those handling outbound mail delivery, should assess their exposure and prioritize verification and [truncated]

HIGH Progressive Robot Ltd CVE published 2026-10-08

CVE-2026-104659

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-10-08T10:52:55.630Z and has not been modified since then. This Origin Validation Error in hMailServer allows remote attackers to brute-force server administrator passwords via DNS rebinding. The vulnerability is due to missing Host header validation and missing throttling of failed administrator sign-i [truncated]

HIGH Progressive Robot Ltd CVE published 2026-10-08

CVE-2026-104660

A local interactive user can exploit a missing authorization vulnerability in Progressive Robot hMailServer 6.0.0 through 6.3.5 to read and write arbitrary files as the service account and queue mail as any sender. This vulnerability allows unauthorized access to sensitive data and potentially leads to code execution as SYSTEM on LocalSystem installations. Defenders should assess exposure and prioritize u [truncated]

HIGH Progressive Robot Ltd CVE published 2026-10-08

CVE-2026-104658

An attacker who already runs code as the hmailserver service account can execute arbitrary code as root on Linux installations where the live update's path unit is active, which is the default for .deb and .rpm packages, and on AppImage installations run under that unit. This vulnerability in hMailServer allows for potential privilege escalation from the hmailserver service account to root. Defenders shou [truncated]

HIGH Progressive Robot Ltd CVE published 2026-10-08

CVE-2026-104704

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-10-08T10:52:40.630Z and has not been modified since then. This vulnerability in hMailServer allows for cleartext transmission of sensitive information, impacting confidentiality and integrity of email communications. Email administrators and security teams should verify configurations, assess exposure, [truncated]