CVE-2026-41113: Sagredo Qmail

High severity, CVSS 8.1. EPSS: 1% chance of exploitation in the next 30 days.

sagredo qmail before 2026.04.07 allows tls_quit remote code execution because of popen in notlshosts_auto in qmail-remote.c.

Affected products

  • Sagredo Qmail: from 2024.10.26, before 2026.04.07 (fixed in 2026.04.07)

Published 2026-04-16. Last modified 2026-06-17.