CVE-2026-35389: Bulwarkmail Webmail
High severity, CVSS 7.5. EPSS: 0.2% chance of exploitation in the next 30 days.
Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, S/MIME signature verification did not validate the certificate trust chain (checkChain: false). Any email signed with a self-signed or untrusted certificate was displayed as having a valid signature. This vulnerability is fixed in 1.4.11.
Affected products
- Bulwarkmail Webmail: before 1.4.11 (fixed in 1.4.11)
Published 2026-04-06. Last modified 2026-07-24.