CVE-2026-27444: Header Email Address Parsing
SEPPmail Secure Email Gateway before version 15.0.1 incorrectly interprets email addresses in the email headers, causing an interpretation conflict with other mail infrastructure that allows an attacker to fake the source of the email or decrypt it.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27444?
CVE-2026-27444 has been classified as a medium severity vulnerability due to its potential to allow email spoofing and decryption.
How do I fix CVE-2026-27444?
To fix CVE-2026-27444, upgrade SEPPmail Secure Email Gateway to version 15.0.1 or later.
What impact does CVE-2026-27444 have on email security?
CVE-2026-27444 can undermine email security by allowing attackers to falsify sender addresses and potentially decrypt emails.
Is CVE-2026-27444 easy to exploit?
Exploiting CVE-2026-27444 requires knowledge of email header manipulation, making it moderately challenging for attackers.
Which versions of SEPPmail Secure Email Gateway are affected by CVE-2026-27444?
CVE-2026-27444 affects all versions of SEPPmail Secure Email Gateway prior to 15.0.1.