New Appliance Release 15.0.7

Information notice SEPPmail Appliances Appliance Release Info

Updates

Information

A new SEPPmail Appliance release has been published. Please see the revision history and the extended release notes for further details.

One important point worth mentioning is that Microsoft has switched to the new DigiCert Global Root G2 Certificate Authority. It is therefore highly recommended that you import this certificate into SEPPmail and mark it as trusted to avoid communication issues with Exchange Online.
More information can be found here.

Admin

  • 64063 - Error while deleting a user
    Fixed an issue that could prevent a local user from being deleted when associated certificate revocation was processed.

  • 63328 - Error while setting time zone
    Fixed an issue that prevented time zone settings from being changed or saved correctly.

Background tasks

  • Log old running refresh_maillog_cache.pl processes
    Improved handling and logging of previously running background processes. This prevents overlapping processes from contributing to excessive resource consumption and system instability.

Cfgserver

  • 63328 - Error while setting time zone
    Fixed an issue that prevented time zone settings from being changed or saved correctly.

Clustering

  • LFM sync not possible because of missing injection connections
    Fixed an issue in the connector.pl service which failed to stop first run injection connections.

Operating system

  • 63155 - Cluster view shows SSH warning for cluster member status
    Updated SSH-related configuration and warning handling to avoid unnecessary warnings when displaying cluster member status.

RestAPI

  • Fix /mailprocessing/ruleset/generate OpenAPI Documentation
    Corrected the API documentation so requests generated according to the specification are accepted as expected.

Rule engine

  • RuleEngine temp directory is not volatile
    Corrected temporary directory handling to ensure required processing data remains available while the Rule Engine instance is in use.

  • 63349 - make_lft() drops old output directory which leads to an empty LFT mail
    Fixed an issue where generated LFT messages could be missing encrypted attachments due to incorrect output directory handling.

  • 63491 - Add specific log output if revocation check is skipped because the next update time for the used CRL is not reached
    Improved logging to provide a clearer explanation when a revocation check is intentionally skipped.

Security

  • OS command injection in privileged configuration handling
    Affected versions: <15.0.7 - CVE-ID: CVE-2026-84830 - CVSS Score: 8.6
    Description: SEPPmail Secure Email Gateway before 15.0.7 contains a command injection vulnerability that allows authenticated administrators to execute commands with elevated privileges.
    Fix Description: All affected values will be escaped not.

  • Bypassing mandatory multi-factor authentication (MFA)
    Affected versions: <15.0.7 - CVE-ID: CVE-2026-84831 - CVSS Score: 7.7
    Description: Under certain conditions, the authentication process could allow a user to gain access before all required multi-factor authentication steps had been completed.
    Fix Description: The authentication flow was tightened to ensure all required MFA checks are completed before access is granted.

  • Unsecure deserialisation in customer import REST endpoint with possible command execution
    Affected versions: <15.0.6 - CVE-ID: CVE-2026-84832 - CVSS Score: 8.6
    Description: A vulnerability in the processing of specially crafted input could potentially lead to unintended command execution in the affected component.
    Fix Description: Additional validation and safer command-handling mechanisms were introduced to prevent malicious input from being executed.

Webmail

  • Processing of hashdecrypt result used wrong secret
    Corrected an issue where cached webmail data could be validated using an incorrect value, potentially preventing it from being processed correctly.

  • Fix Session->set() usage
    Corrected session handling where certain values were not applied as expected, which could cause a session to remain in an incorrect state.

September 3, 2026 · 22:48 CEST

← Back