CVE-2020-26942: Axigen Mail Server

Critical severity, CVSS 9.1. EPSS: 0.5% chance of exploitation in the next 30 days.

An issue discovered in Axigen Mail Server 10.3.x before 10.3.1.27 and 10.3.2.x before 10.3.3.1 allows unauthenticated attackers to submit a setAdminPassword operation request, subsequently setting a new arbitrary password for the admin account.

Affected products

  • Axigen Axigen Mail Server: from 10.3.0, before 10.3.1.27 (fixed in 10.3.1.27); from 10.3.2.0, before 10.3.3.1 (fixed in 10.3.3.1)

Published 2024-03-21. Last modified 2026-06-17.