CVE-2018-16529: Forcepoint Email Security

Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.

A password reset vulnerability has been discovered in Forcepoint Email Security 8.5.x. The password reset URL can be used after the intended expiration period or after the URL has already been used to reset a password.

Affected products

  • Forcepoint Email Security: from 8.5.0, up to and including 8.5.3

Published 2019-03-28. Last modified 2026-06-17.