CVE-2026-50590: Mimecast Incydr

Medium severity, CVSS 4.5. EPSS: 0.1% chance of exploitation in the next 30 days.

In Mimecast Incydr before 2.6.0, arbitrary file access can occur.

Affected products

  • Mimecast Incydr: from 1.2.0, before 2.6.0 (fixed in 2.6.0)

Published 2026-06-05. Last modified 2026-07-23.