logo

Exploited in the Wild: Critical 9.8 CVSS RCE Hits Canon GUARDIANWALL MailSuite

ID: ea3638f0-c7b7-58b3-b875-c7df8abe7092

STIX ID: report--ea3638f0-c7b7-58b3-b875-c7df8abe7092

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-05-14

Date Updated: 2026-05-22

Author: Ddos

...
...

A critical stack-based buffer overflow (CVE-2026-32661, CVSS 9.8) exists in GUARDIANWALL MailSuite's pop3wallpasswd command that allows remote unauthenticated attackers to send specially crafted requests leading to arbitrary code execution when run with grdnwww privileges; the vendor reports active exploitation in the wild, has released patches (SaaS patched on April 30, 2026) and recommends immediate patching or, as a disruptive temporary mitigation, disabling the administration screen (stop /etc/init.d/grdn-wgw-work).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.