CVE-2026-9177
Gravedad CVSS v4.0:
CRÍTICA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
29/07/2026
Última modificación:
30/07/2026
Descripción
*** Pendiente de traducción *** A Server-Side Template Injection (SSTI) vulnerability was identified <br />
in the mail template functionality of the Axway SecureTransport product in version 5.5-20260326. This <br />
flaw <br />
allows an attacker with admin privileges to inject arbitrary Java code expressions, which are <br />
executed server-side when the template is rendered (i.e., during email <br />
sending). Successful exploitation of this flaw allows an attacker to <br />
execute <br />
arbitrary code on the server that results in full host compromise.<br />
<br />
<br />
<br />
This issue affects all Axway SecureTransport versions prior 5.5-20260528 update.
Impacto
Puntuación base 4.0
9.40
Gravedad 4.0
CRÍTICA



