CVE-2026-9177
Severity CVSS v4.0:
CRITICAL
Type:
Unavailable / Other
Publication date:
29/07/2026
Last modified:
30/07/2026
Description
A Server-Side Template Injection (SSTI) vulnerability was identified <br />
in the mail template functionality of the Axway SecureTransport product in version 5.5-20260326. This <br />
flaw <br />
allows an attacker with admin privileges to inject arbitrary Java code expressions, which are <br />
executed server-side when the template is rendered (i.e., during email <br />
sending). Successful exploitation of this flaw allows an attacker to <br />
execute <br />
arbitrary code on the server that results in full host compromise.<br />
<br />
<br />
<br />
This issue affects all Axway SecureTransport versions prior 5.5-20260528 update.
Impact
Base Score 4.0
9.40
Severity 4.0
CRITICAL



