https://seclists.org/oss-sec/2026/q2/493: Dovecot Security Advisory OXDC-2026-0002
Published May 12, 2026
·Updated
Affected Software
2 affected components
Open-Xchange OX Dovecot Pro core<=3.1.4, <=2.3.0, <=3.1.0, <=3.0.5
Open-Xchange OX Dovecot CE core<=2.4.3, <=2.4.0
Frequently Asked Questions
1
What is the severity of OXDC-2026-0002?
The severity of OXDC-2026-0002 is classified as critical due to the potential for remote code execution.
2
How do I fix OXDC-2026-0002?
To fix OXDC-2026-0002, update your Open-Xchange OX Dovecot Pro or CE to the latest patched version.
3
What systems are affected by OXDC-2026-0002?
OXDC-2026-0002 affects both Open-Xchange OX Dovecot Pro core and Open-Xchange OX Dovecot CE core.
4
Have any exploits been reported for OXDC-2026-0002?
Yes, there have been reports of active exploits for OXDC-2026-0002 targeting vulnerable systems.
5
Where can I find more information about OXDC-2026-0002?
More information about OXDC-2026-0002 can be found in the official Dovecot security advisory.