Executive brief
Openfind MailGates and MailAudit, which are email security and auditing solutions, contain a critical vulnerability that allows remote attackers to take full control of the system. An unauthenticated attacker can exploit this flaw over the network to execute malicious code, potentially leading to the theft of sensitive email data or a complete service shutdown. Organizations using these products should update to the latest versions immediately to prevent unauthorized access.
Technical details
A stack-based buffer overflow vulnerability (CWE-121) exists in Openfind MailGates and MailAudit. The flaw allows a remote, unauthenticated attacker to send specially crafted data to the application, leading to memory corruption. By overwriting the stack, an attacker can redirect the program's execution flow to execute arbitrary code with the privileges of the application. The vulnerability affects version 6.0 (prior to 6.1.10.054) and version 5.0 (prior to 5.2.10.099). Patches have been released by the vendor to address this issue.
Affected products
- Openfind MailGates 6.0 before 6.1.10.054, 5.0 before 5.2.10.099
- Openfind MailAudit 6.0 before 6.1.10.054, 5.0 before 5.2.10.099
Timeline
- 2026-04-16: disclosed
- 2026-04-16: advisory
- 2026-04-16: patched