CVE-2026-44126: Insecure deserialization
Published May 8, 2026
·Updated
SEPPmail Secure Email Gateway before version 15.0.4 insecurely deserializes untrusted data, which can be reached from the new GINA UI and may allow unauthenticated remote attackers to execute code via a crafted serialized object.
Affected Software
1 affected component
SEPPmail SEPPmail Secure Email Gateway<15.0.4
Event History
May 8, 2026
CVE Published
via MITRE·01:15 PM
Data Sourced
via MITRE·01:15 PM
DescriptionWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-44126?
CVE-2026-44126 has been classified as a critical vulnerability due to its potential to allow unauthenticated remote code execution.
2
How do I fix CVE-2026-44126?
To fix CVE-2026-44126, upgrade SEPPmail Secure Email Gateway to version 15.0.4 or later.
3
What systems are affected by CVE-2026-44126?
CVE-2026-44126 affects SEPPmail Secure Email Gateway versions prior to 15.0.4.
4
What is the exploitability of CVE-2026-44126?
CVE-2026-44126 is easily exploitable by unauthenticated attackers due to insecure deserialization.
5
What kind of attacks can CVE-2026-44126 enable?
CVE-2026-44126 can enable remote code execution attacks through crafted serialized objects.