CVE-2026-27443: S/MIME Decryption Tag Sanitization Bypass
Published Mar 4, 2026
·Updated
SEPPmail Secure Email Gateway before version 15.0.1 does not properly sanitize the headers from S/MIME protected MIME entities, allowing an attacker to control trusted headers.
Affected Software
2 affected components
SEPPmail Secure Email Gateway<15.0.1
SEPPmail SEPPmail<15.0.1
Event History
Mar 4, 2026
CVE Published
via MITRE·08:45 AM
Data Sourced
via MITRE·08:45 AM
DescriptionWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-27443?
CVE-2026-27443 is classified as a high severity vulnerability due to the potential for remote exploitation.
2
How do I fix CVE-2026-27443?
To mitigate CVE-2026-27443, upgrade SEPPmail Secure Email Gateway to version 15.0.1 or later.
3
What does CVE-2026-27443 exploit?
CVE-2026-27443 exploits improper sanitization of headers from S/MIME protected MIME entities.
4
Who is affected by CVE-2026-27443?
CVE-2026-27443 affects users of SEPPmail Secure Email Gateway versions prior to 15.0.1.
5
What can attackers do with CVE-2026-27443?
Attackers can control trusted headers, potentially leading to various security issues such as phishing or data exfiltration.