All CVEs
Vulnerability intelligence

CVE-2026-7864

CWE-497

SEPPmail Secure Email Gateway before version 15.0.4 exposes server environment variables through an unauthenticated endpoint in the new GINA UI, allowing remote attackers to obtain sensitive system information.

CVSS Score
6.9
Medium
EPSS — Exploit Probability
17%
Riskier than 97% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
unknown
Check vendor advisories
NVD entry PoC / advisory

1 article across 1 outlet · first covered May 19, 2026 · latest May 19, 2026

Coverage timeline