CVE-2026-103010: Progressive Robot Ltd Hmailserver
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
Heap-based buffer overflow in the legacy Blowfish decryption routine (BlowFishEncryptor::DecryptFromString) in Progressive Robot hMailServer 6.0.0 through 6.3.3 on Windows allows a local interactive user with no hMailServer credentials to write bytes of their choosing past the end of a 255-byte heap buffer in the hMailServer service process, which runs as LocalSystem by default. The user does this by passing a long hexadecimal string to the COM method Utilities.BlowfishDecrypt, which checked no authentication. The routine converted hexadecimal input of any length into a fixed 255-byte buffer before decrypting it in place. The result is a denial of service (service crash), and possibly code execution with the privileges of the service account.
Affected products
- Progressive Robot Ltd Hmailserver: from 6.0.0, before 6.3.4 (fixed in 6.3.4)
Published 2026-10-08. Last modified 2026-10-08.