Vulnerabilities
36 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-44400 | MailEnable Enterprise Premium 10.55 and earlier contains an improper authorization vulnerability in the WebAdmin mobile portal that allows attackers to bypass a MailEnable Enterprise Premium 10.55 and earlier contains an improper authorization vulnerability in the WebAdmin mobile portal that allows attackers to bypass authentication checks by reusing AuthenticationToken cookies generated for low-privileged users. Attackers can obtain a token from the WebMail login endpoint using the PersistentLogin parameter and replay it against the WebAdmin portal to perform highly privileged administrative actions. NVD description · AI analysis pending | 8.7 | <1% |
| — | ||
| CVE-2026-32851 | MailEnable versions prior to 10.55 contain a reflected cross-site scripting vulnerability in the webmail interface that allows remote attackers to execute arbit MailEnable versions prior to 10.55 contain a reflected cross-site scripting vulnerability in the webmail interface that allows remote attackers to execute arbitrary JavaScript in a victim's browser by crafting a malicious URL. Attackers can inject malicious code through the StartDate parameter in the FreeBusy.aspx form, which is not properly sanitized before being embedded into dynamically generated JavaScript. NVD description · AI analysis pending | 5.1 | <1% | PoC |
| — | |
| CVE-2025-34421 | MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts to load MEAISP.DLL from its installation directory without sufficient integrity validation or a secure search order. A local attacker with write access to that directory can plant a malicious MEAISP.DLL, which is then loaded on execution, resulting in attacker-controlled code running with the privileges of the process. NVD description · AI analysis pending | 8.5 group max | <1% |
| — | ||
| CVE-2025-34396 | MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts to load MEAINFY.DLL from its application directo without sufficient integrity validation or secure search order. If the DLL is missing or attacker-writable locations in the search path are used, a local attacker with write permissions to the directory can plant a malicious MEAINFY.DLL. When the executable is launched, it loads the attacker-controlled library and executes code with the privileges of the process, enabling local privilege escalation when run with elevated rights. NVD description · AI analysis pending | 8.5 group max | <1% |
| — | ||
| CVE-2025-44148 | Unauthenticated XSS in MailEnable failure.aspx enabling arbitrary code execution MailEnable, a Windows-based mail server platform, contains a cross-site scripting flaw (CWE-79) in its failure.aspx web component in all versions before v10. A remote, unauthenticated attacker can deliver crafted input to failure.aspx, causing attacker-controlled script or code to execute in the context of the affected web interface; notably, the CVSS 9.8 vector requires neither privileges nor user interaction and rates confidentiality, integrity, and availability impact as high. Per the advisory, successful exploitation allows arbitrary code execution, which in a webmail context typically translates to session hijacking, credential theft, or actions taken on behalf of logged-in users. Any organization running MailEnable prior to v10 is affected, with the greatest risk where the webmail/web interface is exposed to the internet. A public proof-of-concept exists on GitHub; the issue is not yet in CISA KEV, but EPSS of 54.7% (99th percentile) indicates an elevated likelihood of exploitation within 30 days. Do: Upgrade all MailEnable deployments to v10 or later, as versions before v10 are affected. Where upgrading is not immediately possible, restrict or gate internet-facing access to the MailEnable webmail/web interface and monitor requests to failure.aspx for crafted or unusual input. Given the public PoC and high EPSS score, prioritize this patch and review internet exposure of any Windows hosting servers running MailEnable. | 9.8 | 55% | PoC |
| large≈10,000–100,000 deployed MailEnable servers, many internet-exposed | |
| CVE-2022-42136 | Authenticated mail users, under specific circumstances, could add files with unsanitized content in public folders where the IIS user had permission to access. Authenticated mail users, under specific circumstances, could add files with unsanitized content in public folders where the IIS user had permission to access. That action, could lead an attacker to store arbitrary code on that files and execute RCE commands. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2019-12924 | MailEnable Enterprise Premium 10.23 was vulnerable to XML External Entity Injection (XXE) attacks that could be exploited by an unauthenticated user. MailEnable Enterprise Premium 10.23 was vulnerable to XML External Entity Injection (XXE) attacks that could be exploited by an unauthenticated user. It was possible for an attacker to use a vulnerability in the configuration of the XML processor to read any file on the host system. Because all credentials were stored in a cleartext file, it was possible to steal all users' credentials (including the highest privileged users). NVD description · AI analysis pending | 9.8 group max | <1% |
| — |