CVE-2017-7440: Gfi Kerio Connect

Medium severity, CVSS 6.5. EPSS: 0.9% chance of exploitation in the next 30 days.

Kerio Connect 8.0.0 through 9.2.2, and Kerio Connect Client desktop application for Windows and Mac 9.2.0 through 9.2.2, when e-mail preview is enabled, allows remote attackers to conduct clickjacking attacks via a crafted e-mail message.

Affected products

  • Gfi Kerio Connect: from 8.0.0, up to and including 9.2.2
  • Gfi Kerio Connect Client: from 9.2.0, up to and including 9.2.2

Published 2017-05-02. Last modified 2026-06-17.