Products › End-user applications
End-user applications
Mail servers and clients, webmail and email filtering gateways.
For example: Exchange, Outlook, Zimbra, Roundcube.
-
16 vulnerabilities added in the last 12 months
-
71 exploited vulnerabilities in the catalog, in total
-
2 added in the last 30 days
Pace of additions
| Period | Vulnerabilities added |
|---|---|
| Sep 9, 2025 to Oct 8, 2025 | 2 |
| Oct 9, 2025 to Nov 7, 2025 | 0 |
| Nov 8, 2025 to Dec 7, 2025 | 0 |
| Dec 8, 2025 to Jan 6, 2026 | 1 |
| Jan 7, 2026 to Feb 5, 2026 | 4 |
| Feb 6, 2026 to Mar 7, 2026 | 3 |
| Mar 8, 2026 to Apr 6, 2026 | 1 |
| Apr 7, 2026 to May 6, 2026 | 2 |
| May 7, 2026 to Jun 5, 2026 | 1 |
| Jun 6, 2026 to Jul 5, 2026 | 0 |
| Jul 6, 2026 to Aug 4, 2026 | 0 |
| Aug 5, 2026 to Sep 3, 2026 | 1 |
| Sep 4, 2026 to Oct 3, 2026 (in progress) | 2 |
Affected brands
In alphabetical order, with their number of vulnerabilities in this category.
- Barracuda Networks 1 vulnerability
- Cisco 2 vulnerabilities · 2 in the last 12 months
- Exim 5 vulnerabilities
- Fortinet 1 vulnerability · 1 in the last 12 months
- Libraesva 1 vulnerability
- MDaemon 1 vulnerability
- Microsoft 21 vulnerabilities · 2 in the last 12 months
- OpenBSD 1 vulnerability
- Qualitia 1 vulnerability
- Roundcube 11 vulnerabilities · 2 in the last 12 months
- SmarterTools 3 vulnerabilities · 3 in the last 12 months
- SonicWall 3 vulnerabilities
- Symantec 1 vulnerability
- Zimbra (Synacor) 19 vulnerabilities · 6 in the last 12 months
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
See also
- Collaboration, telephony and video conferencing 53 vulnerabilities
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.
- Rank 1
Fortinet FortiMailCVE-2026-104286
Fortinet FortiMail Path Traversal Vulnerability
Recently addedHunt for compromise (CISA)
CVSS severity 9.8critical
Added Oct 1, 2026
- Rank 2
Cisco Secure Email GatewayCVE-2026-76461
Cisco Secure Email Gateway SQL Injection Vulnerability
Recently addedHunt for compromise (CISA)
CVSS severity 9.8critical
Added Sep 14, 2026
- Rank 3
SmarterTools SmarterMailCVE-2025-52691
SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability
Ransomware
CVSS severity 10.0critical
Added Jan 26, 2026
- Rank 4
Cisco Secure Email GatewayCVE-2025-20393
Cisco Multiple Products Improper Input Validation Vulnerability
CVSS severity 10.0critical
Added Dec 17, 2025
- Rank 5
Zimbra (Synacor) Collaboration Suite (ZCS)CVE-2020-7796
Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability
CVE from 2020, added in 2026
CVSS severity 9.8critical
Added Feb 17, 2026
- Rank 6
SmarterTools SmarterMailCVE-2026-24423
SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability
Ransomware
CVSS severity 9.8critical
Added Feb 5, 2026
- Rank 7
SmarterTools SmarterMailCVE-2026-23760
SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability
Ransomware
CVSS severity 9.8critical
Added Jan 26, 2026
- Rank 8
Zimbra (Synacor) Collaboration Suite (ZCS)CVE-2026-73570
Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
Hunt for compromise (CISA)
CVSS severity 8.9high
Added Aug 21, 2026
- Rank 9
Microsoft Exchange ServerCVE-2023-21529
Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability
RansomwareCVE from 2023, added in 2026
CVSS severity 8.8high
Added Apr 13, 2026
- Rank 10
Roundcube WebmailCVE-2025-49113
RoundCube Webmail Deserialization of Untrusted Data Vulnerability
CVSS severity 8.8high
Added Feb 20, 2026
Show 61 more vulnerabilities
- Rank 11
Zimbra (Synacor) Collaboration Suite (ZCS)CVE-2025-68645
Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability
CVSS severity 8.8high
Added Jan 22, 2026
- Rank 12
Microsoft Exchange ServerCVE-2026-42897
Microsoft Exchange Server Cross-Site Scripting Vulnerability
CVSS severity 6.1medium
Added May 15, 2026
- Rank 13
Zimbra (Synacor) Collaboration Suite (ZCS)CVE-2025-48700
Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability
CVSS severity 6.1medium
Added Apr 20, 2026
- Rank 14
Zimbra (Synacor) Collaboration Suite (ZCS)CVE-2025-66376
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability
CVSS severity 6.1medium
Added Mar 18, 2026
- Rank 15
Roundcube WebmailCVE-2025-68461
RoundCube Webmail Cross-site Scripting Vulnerability
CVSS severity 6.1medium
Added Feb 20, 2026
- Rank 16
Zimbra (Synacor) Collaboration Suite (ZCS)CVE-2025-27915
Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability
CVSS severity 5.4medium
Added Oct 7, 2025
- Rank 17
Qualitia Active! MailCVE-2025-42599
Qualitia Active! Mail Stack-Based Buffer Overflow Vulnerability
CVSS severity 9.8critical
Added Apr 28, 2025
- Rank 18
Microsoft OutlookCVE-2024-21413
Microsoft Outlook Improper Input Validation Vulnerability
CVSS severity 9.8critical
Added Feb 6, 2025
- Rank 19
Zimbra (Synacor) Collaboration Suite (ZCS)CVE-2024-45519
Synacor Zimbra Collaboration Suite (ZCS) Command Execution Vulnerability
CVSS severity 9.8critical
Added Oct 3, 2024
- Rank 20
Microsoft Exchange ServerCVE-2024-21410
Microsoft Exchange Server Privilege Escalation Vulnerability
CVSS severity 9.8critical
Added Feb 15, 2024
- Rank 21
Roundcube WebmailCVE-2020-12641
Roundcube Webmail Remote Code Execution Vulnerability
CVE from 2020, added in 2023
CVSS severity 9.8critical
Added Jun 22, 2023
- Rank 22
Roundcube WebmailCVE-2021-44026
Roundcube Webmail SQL Injection Vulnerability
CVE from 2021, added in 2023
CVSS severity 9.8critical
Added Jun 22, 2023
- Rank 23
Barracuda Networks Email Security Gateway (ESG)CVE-2023-2868
Barracuda Networks ESG Appliance Improper Input Validation Vulnerability
CVSS severity 9.8critical
Added May 26, 2023
- Rank 24
Microsoft Exchange ServerCVE-2022-41080
Microsoft Exchange Server Privilege Escalation Vulnerability
Ransomware
CVSS severity 9.8critical
Added Jan 10, 2023
- Rank 25
Zimbra (Synacor) Collaboration Suite (ZCS)CVE-2022-41352
Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability
Ransomware
CVSS severity 9.8critical
Added Oct 20, 2022
- Rank 26
Zimbra (Synacor) Collaboration Suite (ZCS)CVE-2022-37042
Synacor Zimbra Collaboration Suite (ZCS) Authentication Bypass Vulnerability
Ransomware
CVSS severity 9.8critical
Added Aug 11, 2022
- Rank 27
EximCVE-2010-4344
Exim Heap-Based Buffer Overflow Vulnerability
CVE from 2010, added in 2022
CVSS severity 9.8critical
Added Mar 25, 2022
- Rank 28
OpenBSD OpenSMTPDCVE-2020-7247
OpenSMTPD Remote Code Execution Vulnerability
CVE from 2020, added in 2022
CVSS severity 9.8critical
Added Mar 25, 2022
- Rank 29
EximCVE-2019-16928
Exim Out-of-bounds Write Vulnerability
CVE from 2019, added in 2022
CVSS severity 9.8critical
Added Mar 3, 2022
- Rank 30
EximCVE-2019-10149
Exim Mail Transfer Agent (MTA) Improper Input Validation
CVE from 2019, added in 2022
CVSS severity 9.8critical
Added Jan 10, 2022
- Rank 31
Zimbra (Synacor) Collaboration Suite (ZCS)CVE-2019-9670
Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference
CVE from 2019, added in 2022
CVSS severity 9.8critical
Added Jan 10, 2022
- Rank 32
EximCVE-2018-6789
Exim Buffer Overflow Vulnerability
RansomwareCVE from 2018, added in 2021
CVSS severity 9.8critical
Added Nov 3, 2021
- Rank 33
SonicWall Email SecurityCVE-2021-20021
SonicWall Email Security Improper Privilege Management Vulnerability
Ransomware
CVSS severity 9.8critical
Added Nov 3, 2021
- Rank 34
Microsoft Exchange ServerCVE-2021-26855
Microsoft Exchange Server Remote Code Execution Vulnerability
Ransomware
CVSS severity 9.8critical
Added Nov 3, 2021
- Rank 35
Microsoft Exchange ServerCVE-2021-34473
Microsoft Exchange Server Remote Code Execution Vulnerability
Ransomware
CVSS severity 9.8critical
Added Nov 3, 2021
- Rank 36
Microsoft Exchange ServerCVE-2021-34523
Microsoft Exchange Server Privilege Escalation Vulnerability
Ransomware
CVSS severity 9.8critical
Added Nov 3, 2021
- Rank 37
Roundcube WebmailCVE-2024-42009
RoundCube Webmail Cross-Site Scripting Vulnerability
CVSS severity 9.3critical
Added Jun 9, 2025
- Rank 38
Zimbra (Synacor) Collaboration Suite (ZCS)CVE-2023-34192
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
CVE from 2023, added in 2025
CVSS severity 9.0critical
Added Feb 25, 2025
- Rank 39
Microsoft Exchange ServerCVE-2022-41040
Microsoft Exchange Server Server-Side Request Forgery Vulnerability
Ransomware
CVSS severity 8.8high
Added Sep 30, 2022
- Rank 40
Microsoft Exchange ServerCVE-2021-42321
Microsoft Exchange Server Remote Code Execution Vulnerability
Ransomware
CVSS severity 8.8high
Added Nov 17, 2021
- Rank 41
Symantec Messaging GatewayCVE-2017-6327
Symantec Messaging Gateway Remote Code Execution Vulnerability
CVE from 2017, added in 2021
CVSS severity 8.8high
Added Nov 3, 2021
- Rank 42
Microsoft Exchange ServerCVE-2020-0688
Microsoft Exchange Server Validation Key Remote Code Execution Vulnerability
Ransomware
CVSS severity 8.8high
Added Nov 3, 2021
- Rank 43
Microsoft Exchange ServerCVE-2020-17144
Microsoft Exchange Server Remote Code Execution Vulnerability
CVSS severity 8.8high
Added Nov 3, 2021
- Rank 44
Microsoft Exchange ServerCVE-2022-41082
Microsoft Exchange Server Remote Code Execution Vulnerability
Ransomware
CVSS severity 8.0high
Added Sep 30, 2022
- Rank 45
EximCVE-2010-4345
Exim Privilege Escalation Vulnerability
CVE from 2010, added in 2022
CVSS severity 7.8high
Added Mar 25, 2022
- Rank 46
Roundcube WebmailCVE-2017-16651
Roundcube Webmail File Disclosure Vulnerability
CVE from 2017, added in 2021
CVSS severity 7.8high
Added Nov 3, 2021
- Rank 47
Microsoft Exchange ServerCVE-2021-26857
Microsoft Exchange Server Remote Code Execution Vulnerability
Ransomware
CVSS severity 7.8high
Added Nov 3, 2021
- Rank 48
Microsoft Exchange ServerCVE-2021-26858
Microsoft Exchange Server Remote Code Execution Vulnerability
Ransomware
CVSS severity 7.8high
Added Nov 3, 2021
- Rank 49
Microsoft Exchange ServerCVE-2021-27065
Microsoft Exchange Server Remote Code Execution Vulnerability
Ransomware
CVSS severity 7.8high
Added Nov 3, 2021
- Rank 50
Zimbra (Synacor) Collaboration Suite (ZCS)CVE-2019-9621
Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability
CVE from 2019, added in 2025
CVSS severity 7.5high
Added Jul 7, 2025
- Rank 51
Microsoft OutlookCVE-2023-35311
Microsoft Outlook Security Feature Bypass Vulnerability
CVSS severity 7.5high
Added Jul 11, 2023
- Rank 52
Zimbra (Synacor) Collaboration Suite (ZCS)CVE-2022-27924
Synacor Zimbra Collaboration Suite (ZCS) Command Injection Vulnerability
Ransomware
CVSS severity 7.5high
Added Aug 4, 2022
- Rank 53
Microsoft Exchange ServerCVE-2021-33766
Microsoft Exchange Server Information Disclosure
CVSS severity 7.5high
Added Jan 18, 2022
- Rank 54
Microsoft Exchange ServerCVE-2018-8581
Microsoft Exchange Server Privilege Escalation Vulnerability
RansomwareCVE from 2018, added in 2022
CVSS severity 7.4high
Added Mar 3, 2022
- Rank 55
Microsoft Exchange ServerCVE-2021-31196
Microsoft Exchange Server Information Disclosure Vulnerability
CVE from 2021, added in 2024
CVSS severity 7.2high
Added Aug 21, 2024
- Rank 56
Zimbra (Synacor) Collaboration Suite (ZCS)CVE-2022-27925
Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability
Ransomware
CVSS severity 7.2high
Added Aug 11, 2022
- Rank 57
SonicWall Email SecurityCVE-2021-20022
SonicWall Email Security Unrestricted Upload of File Vulnerability
Ransomware
CVSS severity 7.2high
Added Nov 3, 2021
- Rank 58
Microsoft Exchange ServerCVE-2021-31207
Microsoft Exchange Server Security Feature Bypass Vulnerability
Ransomware
CVSS severity 6.6medium
Added Nov 3, 2021
- Rank 59
Libraesva Email Security GatewayCVE-2025-59689
Libraesva Email Security Gateway Command Injection Vulnerability
CVSS severity 6.1medium
Added Sep 29, 2025
- Rank 60
MDaemon Email ServerCVE-2024-11182
MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability
CVSS severity 6.1medium
Added May 19, 2025
- Rank 61
Zimbra (Synacor) Collaboration Suite (ZCS)CVE-2024-27443
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
CVSS severity 6.1medium
Added May 19, 2025
- Rank 62
Roundcube WebmailCVE-2024-37383
RoundCube Webmail Cross-Site Scripting (XSS) Vulnerability
CVSS severity 6.1medium
Added Oct 24, 2024
- Rank 63
Roundcube WebmailCVE-2020-13965
Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability
CVE from 2020, added in 2024
CVSS severity 6.1medium
Added Jun 26, 2024
- Rank 64
Roundcube WebmailCVE-2023-43770
Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability
CVSS severity 6.1medium
Added Feb 12, 2024
- Rank 65
Zimbra (Synacor) Collaboration Suite (ZCS)CVE-2023-37580
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
CVSS severity 6.1medium
Added Jul 27, 2023
- Rank 66
Roundcube WebmailCVE-2020-35730
Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability
CVE from 2020, added in 2023
CVSS severity 6.1medium
Added Jun 22, 2023
- Rank 67
Zimbra (Synacor) Collaboration Suite (ZCS)CVE-2022-27926
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
CVSS severity 6.1medium
Added Apr 3, 2023
- Rank 68
Zimbra (Synacor) Collaboration Suite (ZCS)CVE-2018-6882
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
RansomwareCVE from 2018, added in 2022
CVSS severity 6.1medium
Added Apr 19, 2022
- Rank 69
Zimbra (Synacor) Collaboration Suite (ZCS)CVE-2022-24682
Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability
Ransomware
CVSS severity 6.1medium
Added Feb 25, 2022
- Rank 70
Roundcube WebmailCVE-2023-5631
Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability
CVSS severity 5.4medium
Added Oct 26, 2023
- Rank 71
SonicWall Email SecurityCVE-2021-20023
SonicWall Email Security Path Traversal Vulnerability
Ransomware
CVSS severity 4.9medium
Added Nov 3, 2021
Filed under another category
These 9 vulnerabilities also concern this type of product, but are counted in their main category. My radar finds them when you follow this category.
Mozilla FirefoxCVE-2010-3765
Mozilla Multiple Products Remote Code Execution Vulnerability
CVE from 2010, added in 2025
CVSS severity 9.8critical
Added Oct 6, 2025
Mozilla FirefoxCVE-2019-11708
Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability
CVE from 2019, added in 2022
CVSS severity 10.0critical
Added May 23, 2022
Fortinet FortiVoice / FortiFoneCVE-2025-32756
Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability
CVSS severity 9.8critical
Added May 14, 2025
Mozilla FirefoxCVE-2019-11707
Mozilla Firefox and Thunderbird Type Confusion Vulnerability
CVE from 2019, added in 2022
CVSS severity 8.8high
Added May 23, 2022
Mozilla FirefoxCVE-2013-1690
Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability
CVE from 2013, added in 2022
CVSS severity 8.8high
Added Mar 28, 2022
Show 4 more vulnerabilities
Mozilla FirefoxCVE-2019-17026
Mozilla Firefox And Thunderbird Type Confusion Vulnerability
CVE from 2019, added in 2021
CVSS severity 8.8high
Added Nov 3, 2021
Mozilla FirefoxCVE-2020-6819
Mozilla Firefox And Thunderbird Use-After-Free Vulnerability
CVSS severity 8.1high
Added Nov 3, 2021
Mozilla FirefoxCVE-2020-6820
Mozilla Firefox And Thunderbird Use-After-Free Vulnerability
CVSS severity 8.1high
Added Nov 3, 2021
Mozilla FirefoxCVE-2016-9079
Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability
CVE from 2016, added in 2023
CVSS severity 7.5high
Added Jun 22, 2023
Follow and verify
Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).
Indicative classification, based on the vendor and product names given by CISA. How products are classified.