#SEPPMail
Bei #SEPPmail mit «100 % Sicherheit» wurden schwerwiegende Sicherheitslücken 🔓 entdeckt.

In den aktuellen «Datenschutz-Plaudereien» spreche ich 🎙️ mit Matthias Leisi, dem CTO von SEPPmail, ausführlich über die Sicherheitslücken.

Jetzt reinhören! 🎧

podcast.datenschutzpartner.ch/401-matthias...
DAT401 Was sagt SEPPmail zu den Sicherheitslücken? (Matthias Leisi)
Bei SEPPmail, einem angeblich sicheren E‑Mail-Dienst, fanden Forschende der ETH Zürich und andere Fachpersonen schwerwiegende Sicherheitslücken. Im Gespräch mit Martin Steiger nimmt Matthias Leisi, CT...
podcast.datenschutzpartner.ch
May 18, 2026 at 8:23 AM
Our latest “Crypto in the Wild” project, analysing secure email gateways. We give 29 cryptographic attacks on 4 different products, from SEPPmail, Cisco, Proton and CipherMail. Paper to appear at ACM CCS 2026.
Why Johnny Should Not Delegate Email Encryption to Gateways (Andris Suter-Dörig, Matteo Scarlata, Kenneth G. Paterson) ia.cr/2026/1911
September 10, 2026 at 8:12 AM
Seppmail wtf
August 23, 2025 at 6:06 PM
#SEPPmail wirbt mit 100 % Sicherheit bei der Kommunikation, hat aber viele schwerwiegende Sicherheitslücken … 😬

In den aktuellen «Datenschutz-Plaudereien», übrigens ist das Folge 400! 🎂, sprechen wir über diesen Totalschaden:

podcast.datenschutzpartner.ch/400-seppmail...
DAT400 SEPPmail mit schwerwiegenden Sicherheitslücken
SEPPmail verspricht seit über 20 Jahren sichere E‑Mail, aktuell unter anderem: «Vollumfängliche E‑Mail-Sicherheit», «Compliant E-Mail-Kommunikation (DSGVO-Konform)» und «100 % sichere Kommunikation». ...
podcast.datenschutzpartner.ch
May 11, 2026 at 9:10 AM
If you want to be truly terrified, check out Andris’ Master’s thesis, where he reports 56 vulnerabilities against SEPPmail, including RCE. ethz.ch/content/dam/...
ethz.ch
September 10, 2026 at 8:21 AM
E-Mail-Sicherheit in der Cloud darf nicht am Postfach enden

#Cybersecurity #Cybersicherheit #EMail #EMailSicherheit #Malware #Phishing @Seppmail #spam

netzpalaver.de/2026/...
September 23, 2026 at 2:11 PM
Kunde: Wie schreib ich "Seppmail"? mit Z? Ich find es nicht.
Ich: nein wie Franz
Kunde: Ah
July 21, 2025 at 6:43 PM
July 22, 2025 at 2:07 PM
Critical SEPPmail Gateway Flaws Allow Remote Code Execution and Mail Traffic Theft
Critical SEPPmail Gateway Flaws Allow Remote Code Execution and Mail Traffic Theft
Critical vulnerabilities in the SEPPmail Secure Email Gateway have exposed organizations to remote code execution (RCE) and potential interception of sensitive email traffic. Researchers uncovered several high-impact flaws affecting SEPPmail appliances, widely deployed across the DACH region. The most severe issues include: CVE-2026-2743: Pre-authenticated RCE via arbitrary file write in the Large File Transfer (LFT) component. CVE-2026-44128: Unauthenticated RCE through Perl code injection. CVE-2026-44127: Local File Inclusion (LFI) enabling access to sensitive files and emails. CVE-2026-7864: Exposure of sensitive environment variables without authentication. These vulnerabilities affect versions before the patched releases in the 15.x branch. SEPPmail Gateway Flaws Path Traversal to Full RCE The most critical flaw, CVE-2026-2743, affects the LFT feature used to handle large email attachments. The backend fails to sanitize user-supplied file paths during uploads, allowing attackers to exploit directory-traversal sequences such as “../”. This enables arbitrary file writes outside the intended directory. Researchers demonstrated that attackers could overwrite the system file /etc/syslog.conf, which is writable by the low-privileged “nobody” user.  Unsanitized Path Traversal (Source: Infoguard) By injecting malicious configuration entries into syslog, attackers can force the system to execute arbitrary commands. For example, a crafted payload can trigger a reverse shell when system logs are processed. The attack chain is completed when log rotation (via newsyslog) reloads the modified configuration, effectively executing the malicious code without requiring authentication. GINA V2 Vulnerabilities The newer GINA V2 web interface introduces additional critical issues: Perl Injection (CVE-2026-44128): Unsanitized input passed directly to a Perl eval() function allows full command execution. LFI and Arbitrary File Access (CVE-2026-44127): Attackers can read sensitive files, including LDAP databases, emails, and credentials. Debug Exposure (CVE-2026-7864): Unauthenticated endpoints leak environment variables, aiding further exploitation. Notably, some of these endpoints lack proper authentication checks, significantly lowering the barrier for attackers. Successful exploitation allows attackers to: Gain full control over the email gateway. Intercept, read, or modify encrypted email traffic. Access credentials, keys, and internal communications. Establish persistent access within the network. Because SEPPmail appliances often operate as black-box virtual systems , security teams may have limited visibility into ongoing attacks. Organizations using SEPPmail should take immediate action: Upgrade to the latest patched version (15.0.4 or later, where applicable). Disable unused features like LFT and GINA V2 if not required. Restrict access to exposed API endpoints. Monitor logs for unusual activity or forced log rotations. Conduct internal audits for potential compromise. According to recent research published by Infoguard Labs , even widely trusted secure email solutions can contain critical security flaws. It also underscores the growing role of AI-assisted vulnerability discovery, which is significantly accelerating both identification and exploitation timelines. Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates. The post Critical SEPPmail Gateway Flaws Allow Remote Code Execution and Mail Traffic Theft appeared first on Cyber Security News .
cybersecuritynews.com
May 19, 2026 at 11:13 AM
SEPPmail auf der Enforce Tac 2026: Cybersicherheit als Schlüsselkomponente moderner Verteidigungsfähigkeit #IT #Software
SEPPmail auf der Enforce Tac 2026: Cybersicherheit als Schlüsselkomponente moderner Verteidigungsfähigkeit
Artikel von SEPPmail Deutschland GmbH
dlvr.it
January 20, 2026 at 10:04 AM
Waren sie sich besser bei seppmail.
January 29, 2026 at 12:00 PM
SEPPmail auf der Public-IT-Security 2026: sichere E-Mail-Kommunikation für Behörden und öffentliche Verwaltung #IT #Software
SEPPmail auf der Public-IT-Security 2026: sichere E-Mail-Kommunikation für Behörden und öffentliche Verwaltung
Artikel von SEPPmail Deutschland GmbH
dlvr.it
June 3, 2026 at 11:35 AM
August 25, 2025 at 3:02 PM
E-Mail-Security-Spezialist Seppmail beruft neuen CEO und stärkt Fokus auf E-Mail-Security und Data-Sovereignty

#CEO #Cybersecurity #Cybersicherheit #DataSovereignty #EMailSecurity @Seppmail

netzpalaver.de/2026/...
May 6, 2026 at 2:45 PM
August 12, 2025 at 12:18 PM
🚨 EUVD-2026-9794
📊 10.0/10
🏢 SEPPmail

📝 Arbitrary File Write via Path Traversal upload to Remote Code Execution in SeppMail User Web Interface. The affected feature is the large file transfer (L...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-9794

#cybersecurity #infosec #cve #euvd
March 5, 2026 at 8:08 AM
In unserer Interview-Serie zum Thema KI kommt hier Günter Esch, Geschäftsführer SEPPmail Deutschland GmbH, zu Wort.
www.sysbus.eu/?p=28611
March 6, 2025 at 7:58 AM
July 15, 2026 at 12:22 PM
Advent, Advent das Postfach brennt - Hochkonjunktur für Cyberattacken in der Weihnachtszeit

#Cyberattacke #Cybersecurity #Cybersicherheit #EMail #EMailSecurity #EMailSicherheit #Monitoring @Seppmail #Verschlüsselung #Weihnachtszeit

netzpalaver.de/2025/...
December 4, 2025 at 1:58 PM
April 10, 2026 at 11:58 AM
🤖 High-Severity Bug in VMware vCenter Exposed to RCE

📝 Attackers exploit unpatched vCenter servers to gain remote code execution access.

https://thehackernews.com/2026/05/seppmail-secure-e-mail-gateway.html

📰 The Hacker News

#AI #ZeroDay
SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access
Critical security vulnerabilities have been disclosed in SEPPMail Secure E-Mail Gateway, an enterprise-grade email security solution, that could be exploited to achieve remote code execution and enabl
thehackernews.com
May 19, 2026 at 1:05 PM
Why Johnny Should Not Delegate Email Encryption to Gateways (Andris Suter-Dörig, Matteo Scarlata, Kenneth G. Paterson) ia.cr/2026/1911
September 10, 2026 at 8:07 AM
E-Mail-Sicherheit: Schutz vor KI-gesteuerten Cyberbedrohungen hat höchste Priorität #IT #Software
E-Mail-Sicherheit: Schutz vor KI-gesteuerten Cyberbedrohungen hat höchste Priorität
Pressemitteilung von SEPPmail Deutschland GmbH
dlvr.it
March 11, 2025 at 9:20 AM
Wenn Kommunikation verloren geht: die unterschätzte Bedeutung von E-Mail-Backups #IT #Software
Wenn Kommunikation verloren geht: die unterschätzte Bedeutung von E-Mail-Backups
Artikel von SEPPmail Deutschland GmbH
dlvr.it
March 25, 2026 at 11:05 AM