ZeroHour

CVE-2026-82082

niche

Unauthenticated OS Command Injection RCE in Green-Computing NUMail

CVSS 4.0
9.3 critical
EPSS
1%p73
Published
()
Modified
AI analysis

NUMail, a mail server product from Taiwan-based vendor Green-Computing, contains an OS command injection flaw (CWE-78) that allows an unauthenticated remote attacker to inject arbitrary operating system commands into server-side command calls. The flaw is reachable over the network with no privileges or user interaction required (CVSS 4.0 AV:N/PR:N/UI:N), so a single crafted request can trigger it. Successful exploitation yields execution of arbitrary commands on the underlying server, giving the attacker high-impact control over confidentiality, integrity, and availability of the host and the mail data it holds. Any organization running NUMail is affected; the vendor's advisory (coordinated by Taiwan's CERT, twcert) applies to deployments of this product and no specific unaffected version ranges are available in the current data. There is no public proof-of-concept and the flaw is not in CISA KEV; EPSS assigns a 1.5% chance of exploitation within 30 days (73rd percentile), indicating moderate but not yet observed exploitation risk.

What to do: Monitor the Green-Computing NUMail vendor advisory and the twcert (TVN/CVE-2026-82082) announcement for the patched version and apply the update as soon as it is released, since no fixed version is named in current data. In the meantime, restrict network access to NUMail's externally reachable services (firewall/ACL or VPN, allow-listing trusted sources) to reduce unauthenticated exposure, and check internet-exposed mail servers for signs of unexpected process or command execution. Given the 9.3 critical score and unauthenticated network vector, prioritize patching if NUMail is exposed to the internet.

Affected
Green-Computing NUMail
Estimated exposure
nichelikely hundreds to low thousands of deployments (unknown; regional Taiwan mail-server product with no public install or internet-exposure counts) — No public active-install, telemetry, or internet-scan counts exist for NUMail, so the estimate rests on its status as a niche mail server from a Taiwan-focused vendor (CNA is [email protected]), typically deployed by organizations in that…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

NUMail developed by Green-Computing has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server.

Weakness
CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.