Skip to content
Critical RCE Vulnerabilities in AcyMailing and GestSup Exploited via Email Attachments

Critical RCE Vulnerabilities in AcyMailing and GestSup Exploited via Email Attachments

First seen 26 Sep 2026, 23:50 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 27, 2026 at 22:57 UTC
  • •CVE-2026-94132 allows RCE via unvalidated MIME attachments in AcyMailing.
  • •CVE-2026-100389 enables RCE through unauthenticated email attachments in GestSup.
  • •Both vulnerabilities have critical CVSS scores and are actively discussed on social media.

Two critical remote code execution vulnerabilities have been disclosed affecting AcyMailing Enterprise and GestSup. CVE-2026-94132, affecting AcyMailing versions below 11.1.0, allows attackers to exploit unvalidated MIME attachments in POP3 mode, achieving RCE. CVE-2026-100389 in GestSup versions before 3.2.61 similarly allows unauthenticated attackers to send PHP attachments to monitored mailboxes, which are then executed. Both vulnerabilities have received significant attention, with CVSS scores of 9.5 and 9.2 respectively. A proof-of-concept (PoC) for CVE-2026-94132 was released on September 27, 2026, indicating active exploitation potential. Organizations using these systems are urged to update or mitigate the vulnerabilities immediately. The vulnerabilities are particularly concerning due to their ease of exploitation through email.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 19h ago How this analysis works

Timeline

2026-09-25
CVE-2026-100389 published
GestSup versions before 3.2.61 disclosed with RCE vulnerability in IMAP attachment handling.
Mondoo
2026-09-26
CVE-2026-94132 published
AcyMailing Enterprise for Joomla < 11.1.0 disclosed with RCE vulnerability in mailbox actions.
Sploitus
2026-09-27
PoC for CVE-2026-94132 released
Public proof-of-concept code for exploiting AcyMailing vulnerability made available.
Sploitus

More articles in this cluster (8)

Following this threat?

Track CVE-2026-100389 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed