Critical Vulnerability CVE-2026-2743 in SeppMail Exposes Users to Remote Code Execution

Critical Vulnerability CVE-2026-2743 in SeppMail Exposes Users to Remote Code Execution

First seen 8 Jun 2026, 10:17 UTC Strobes.Convd.nist.govrules.emergingthreats.net 81% similarity 75.0

Article Content

Browse articles
ThreatCluster

CVE-2026-2743 is a critical vulnerability with a CVSS score of 9.8, affecting SeppMail versions 15.0.2.1 and earlier. The vulnerability allows arbitrary file write via path traversal, leading to potential remote code execution through the large file transfer feature. Active exploits have been reported, and no official patch is currently available, necessitating immediate mitigation efforts. The EPSS indicates a 30-day exploitation probability, emphasizing the urgency of addressing this issue. Security professionals are advised to validate their environments against this vulnerability using available tools. The vulnerability was published on March 5, 2026, and has since been updated with enrichment data from the NVD.

Key Points: • CVE-2026-2743 has a CVSS score of 9.8, indicating critical severity. • The vulnerability allows remote code execution via arbitrary file write in SeppMail. • Immediate mitigation is required as active exploits are confirmed and no patch is available.

ThreatCluster AI

Timeline

2026-03-05
CVE-2026-2743 published
CVE-2026-2743 was officially published, detailing a critical vulnerability in SeppMail.
Strobes.Co
2026-06-07
Active exploits reported
Reports indicate that active exploits for CVE-2026-2743 are being utilized against vulnerable systems.
Strobes.Co
2026-06-08
NVD updates CVE record
The NVD updated the CVE record for CVE-2026-2743 after enrichment efforts were completed.
nvd.nist.gov

Community

Browse all →

Tracked Entities in This Story