PublicCVE

CVE-2025-52691

CRITICAL10.0Remote code exec
CISA KEVRansomwarePublic PoCHigh EPSS

Description

Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.

CVSS breakdown

CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Affected products

Exploits & proofs of concept