CVE-2023-39699: Icewarp Mail Server

Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.

IceWarp Mail Server v10.4.5 was discovered to contain a local file inclusion (LFI) vulnerability via the component /calendar/minimizer/index.php. This vulnerability allows attackers to include or execute files from the local file system of the targeted server.

Affected products

  • Icewarp Mail Server: version 10.4.5 only

Published 2023-08-25. Last modified 2026-06-17.