PatchSiren

SEPPmail CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL SEPPmail CVE published 2026-05-08

CVE-2026-44128

CVE-2026-44128 is a critical remote code execution issue in SEPPmail Secure Email Gateway before version 15.0.2.1. The supplied description says a new GINA UI endpoint passes attacker-controlled input from a parameter into Perl's eval(), which can let an unauthenticated remote attacker execute code on the appliance. Based on the published CVSS 9.3 score and NVD record, this is an urgent exposure for any o [truncated]