CVE-2026-2748: S/MIME Certificate Subject Whitespace
Published Mar 4, 2026
·Updated
SEPPmail Secure Email Gateway before version 15.0.1 improperly validates S/MIME certificates issued for email addresses containing whitespaces, allowing signature spoofing.
Affected Software
2 affected components
SEPPmail Secure Email Gateway<15.0.1
SEPPmail SEPPmail<15.0.1
Event History
Mar 4, 2026
CVE Published
via MITRE·08:48 AM
Data Sourced
via MITRE·08:48 AM
DescriptionWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-2748?
CVE-2026-2748 has a high severity rating due to its potential for allowing signature spoofing through improperly validated S/MIME certificates.
2
How do I fix CVE-2026-2748?
To fix CVE-2026-2748, upgrade your SEPPmail Secure Email Gateway to version 15.0.1 or later.
3
What systems are affected by CVE-2026-2748?
CVE-2026-2748 affects SEPPmail Secure Email Gateway versions prior to 15.0.1.
4
What kind of attack does CVE-2026-2748 facilitate?
CVE-2026-2748 facilitates signature spoofing attacks due to improper validation of whitespaces in email addresses.
5
What should organizations using SEPPmail Secure Email Gateway do regarding CVE-2026-2748?
Organizations using SEPPmail Secure Email Gateway should immediately upgrade to version 15.0.1 to mitigate the risk associated with CVE-2026-2748.