Exploited in the Wild: Critical 9.8 CVSS RCE Hits Canon GUARDIANWALL MailSuite
ID: ea3638f0-c7b7-58b3-b875-c7df8abe7092
STIX ID: report--ea3638f0-c7b7-58b3-b875-c7df8abe7092
Feed Name: securityonline.info
A critical stack-based buffer overflow (CVE-2026-32661, CVSS 9.8) exists in GUARDIANWALL MailSuite's pop3wallpasswd command that allows remote unauthenticated attackers to send specially crafted requests leading to arbitrary code execution when run with grdnwww privileges; the vendor reports active exploitation in the wild, has released patches (SaaS patched on April 30, 2026) and recommends immediate patching or, as a disruptive temporary mitigation, disabling the administration screen (stop /etc/init.d/grdn-wgw-work).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
