← Terug naar overzicht

NUMail, an email application developed by Green-Computing, contains a critical OS Command Injection vulnerability tracked as CVE-2026-82082. The vulnerability allows unauthenticated remote attackers to inject and execute arbitrary OS commands on the affected server. No authentication is required to exploit this flaw, making it particularly dangerous as any remote attacker can leverage it. Successful exploitation could result in full server compromise, data exfiltration, or further lateral movement within a network. The vulnerability has been reported via Taiwan's TWCERT/CC advisory system, suggesting the product may be primarily used in Taiwan or the Asia-Pacific region. The issue highlights the risk of improper input sanitization in mail server applications. Organizations using NUMail by Green-Computing should apply patches or mitigations immediately given the critical nature of unauthenticated remote code execution.

Affected products

  • NUMail by Green-Computing

Related CVE's

  • CVE-2026-82082

Categories

  • Email & Messaging
  • Web Technologies
  • Zero-Day Vulnerabilities