CVE-2026-2743: Seppmail

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

Arbitrary File Write via Path Traversal upload to Remote Code Execution in SeppMail User Web Interface. The affected feature is the large file transfer (LFT). This issue affects SeppMail: 15.0.2.1 and before

Affected products

  • Seppmail Seppmail: up to and including 15.0.2.1

Published 2026-03-05. Last modified 2026-06-17.