CVE-2026-9177

Severity CVSS v4.0:
CRITICAL
Type:
Unavailable / Other
Publication date:
29/07/2026
Last modified:
30/07/2026

Description

A Server-Side Template Injection (SSTI) vulnerability was identified <br /> in the mail template functionality of the Axway SecureTransport product in version 5.5-20260326. This <br /> flaw <br /> allows an attacker with admin privileges to inject arbitrary Java code expressions, which are <br /> executed server-side when the template is rendered (i.e., during email <br /> sending). Successful exploitation of this flaw allows an attacker to <br /> execute <br /> arbitrary code on the server that results in full host compromise.<br /> <br /> <br /> <br /> This issue affects all Axway SecureTransport versions prior 5.5-20260528 update.