{"services":[{"id":5630,"name":"Global Services","description":null,"children":[{"id":5487,"name":"Login Page","description":null,"children":[],"current_incident_type":null},{"id":5485,"name":"Cloud REST API","description":null,"children":[],"current_incident_type":null},{"id":10454,"name":"Quarantine Reports","description":null,"children":[],"current_incident_type":null},{"id":11469,"name":"2FA SMS Service Provider","description":"Service Provider to send two-factor authentication via SMS","children":[],"current_incident_type":null},{"id":13415,"name":"Swisssign Certificate Authority","description":null,"children":[],"current_incident_type":null},{"id":36484,"name":"Support Availability","description":null,"children":[],"current_incident_type":null}],"current_incident_type":null},{"id":5631,"name":"CH Instance","description":null,"children":[{"id":5481,"name":"Mailflow CH Instance","description":null,"children":[],"current_incident_type":null},{"id":5488,"name":"GINA Interface","description":null,"children":[],"current_incident_type":null}],"current_incident_type":null},{"id":5632,"name":"EU Instance","description":null,"children":[{"id":5629,"name":"Mailflow EU Instance","description":null,"children":[],"current_incident_type":null},{"id":35024,"name":"GINA Interface DE","description":null,"children":[],"current_incident_type":null}],"current_incident_type":null},{"id":7558,"name":"External Services","description":"Services external to seppmail.cloud for which SEPPmail is not directly responsible. This section is used to notify about incidents involving third-party services which may impact our partners and customers.","children":[{"id":7559,"name":"M365 Mailhosting","description":"Mailflow to or from Microsoft365","children":[],"current_incident_type":null},{"id":7561,"name":"DNS-Providers","description":"DNS-related providers (registrars, hosting of authoritative zones, ISP or independent resolver services)","children":[],"current_incident_type":null},{"id":21254,"name":"Non-SEPPmail-related incidents","description":"We list incidents which are not directly related to SEPPmail, but which may have an impact on customers under this service. Examples include, but are not limited to: new botnets or spam waves, major security threats involving e-mail services, outages of globally or locally relevant major services.","children":[],"current_incident_type":null}],"current_incident_type":null},{"id":27401,"name":"SEPPmail Appliances","description":null,"children":[{"id":27402,"name":"Licence and Update Services","description":null,"children":[],"current_incident_type":null},{"id":27403,"name":"Appliance Release Info","description":null,"children":[],"current_incident_type":null}],"current_incident_type":null},{"id":33271,"name":"Website","description":null,"children":[],"current_incident_type":null}],"status_page":{"name":"SEPPmail","url":"www.seppmail.com","subdomain":"seppmail","time_zone":"Europe/Zurich","current_incident_type":null,"default_lang":"en"},"incidents":[],"info_notices":[{"id":250062,"title":"New Appliance Release 15.1.0.1","url":"https://seppmail.statuspal.eu/info_notices/250062","updates":[{"id":530580,"type":"info","description":"A new SEPPmail Appliance release has been published. Please see the [revision history](https://docs.seppmail.com/ch/20_revision-history.html) and the [extended release notes](https://downloads.seppmail.com/extrelnotes/151/ERN15.1.html) for further details.\r\n\r\nA quick-fix release for 15.1.0 was necessary because of an error in the GINA domain settings page in the Admin GUI.\r\n\r\n---\r\n##### Hotfix release 15.1.0.1 (Released 2026-09-29)\r\n\r\n###### Admin\r\n\r\n- Fixed internal server error in edit GINA domain page.\r\n\r\n---\r\n\r\n##### Release 15.1.0 (Released 2026-09-28)\r\n\r\n###### Admin\r\n\r\n- Improved monitoring of LDAP database growth to help detect abnormal storage increases before available disk space becomes critical.\r\n- Improved tenant-specific administration so delegated administrators can access only the accounts associated with their assigned tenant.\r\n- Added a connection test for external keyserver settings to simplify configuration verification.\r\n\r\n###### Background tasks\r\n\r\n- Added improved administrator notification when an email backup cannot be completed.\r\n- Added support for notifying communication partners about expiring certificates and facilitating certificate renewal.\r\n- Extended disk-space monitoring to provide notifications when the LFM storage area approaches its configured capacity limit.\r\n\r\n###### Database\r\n\r\n- Adjusted LDAP synchronization settings to improve operation on medium and large installations.\r\n\r\n###### Libraries\r\n\r\n- Update OpenSSL to version 3.5.8\r\n- Update OpenSSH sshd to version 10.4\r\n\r\n###### RestAPI\r\n\r\n- Added auditing capabilities for REST API requests to improve traceability of API activity.\r\n- Corrected an incomplete API definition for cryptographic certificate information.\r\n\r\n###### Rule engine\r\n\r\n- Added message metadata that records actions performed during mail processing, allowing downstream applications to identify how a message was handled.\r\n- Added PostgreSQL integration capabilities for Rule Engine custom commands, enabling controlled database lookups and updates for supported use cases.\r\n\r\n###### Refactoring\r\n\r\n- Modernized the internal implementation used for certificate revocation checks.\r\n\r\n###### Security\r\n\r\n- **Affected versions:** ≤15.0.6.1 - **CVE-ID:** Pending - **CVSS Score:** 9.9  \r\n  **Description:** Insufficient authorization controls in a cryptographic management API could allow an authenticated user with limited permissions to perform operations beyond their intended scope, potentially affecting system-wide trust configuration.  \r\n  **Fix Description:** Restrict access to the REST endpoint `/crypto/rootca` to MSP tokens.\r\n\r\n- **Affected versions:** ≤15.1.0 - **CVE-ID:** Pending - **CVSS Score:** 7.1  \r\n  **Description:** Insufficient output sanitization in the log viewer could allow specially crafted message data to execute unintended browser-side content when viewed by an administrator.  \r\n  **Fix Description:** Escape all external data to prevent content execution.\r\n\r\n- Updated internal command execution to use safer command-handling mechanisms.\r\n\r\n###### Webmail\r\n\r\n- Corrected the styling of generated email notifications to ensure a consistent appearance.\r\n- Added support for restricting file types that external communication partners can upload through GINA.","inserted_at":"2026-09-29T07:23:23","updated_at":"2026-09-29T14:49:04","posted_at":"2026-09-29T07:18:11","subscribers_notified_at":"2026-09-29T07:23:23","description_html":"<p>\nA new SEPPmail Appliance release has been published. Please see the <a target=\"_blank\" href=\"https://docs.seppmail.com/ch/20_revision-history.html\">revision history</a> and the <a target=\"_blank\" href=\"https://downloads.seppmail.com/extrelnotes/151/ERN15.1.html\">extended release notes</a> for further details.</p>\n<p>\nA quick-fix release for 15.1.0 was necessary because of an error in the GINA domain settings page in the Admin GUI.</p>\n<hr class=\"thin\" />\n<h5>\nHotfix release 15.1.0.1 (Released 2026-09-29)</h5>\n<h6>\nAdmin</h6>\n<ul>\n  <li>\nFixed internal server error in edit GINA domain page.  </li>\n</ul>\n<hr class=\"thin\" />\n<h5>\nRelease 15.1.0 (Released 2026-09-28)</h5>\n<h6>\nAdmin</h6>\n<ul>\n  <li>\nImproved monitoring of LDAP database growth to help detect abnormal storage increases before available disk space becomes critical.  </li>\n  <li>\nImproved tenant-specific administration so delegated administrators can access only the accounts associated with their assigned tenant.  </li>\n  <li>\nAdded a connection test for external keyserver settings to simplify configuration verification.  </li>\n</ul>\n<h6>\nBackground tasks</h6>\n<ul>\n  <li>\nAdded improved administrator notification when an email backup cannot be completed.  </li>\n  <li>\nAdded support for notifying communication partners about expiring certificates and facilitating certificate renewal.  </li>\n  <li>\nExtended disk-space monitoring to provide notifications when the LFM storage area approaches its configured capacity limit.  </li>\n</ul>\n<h6>\nDatabase</h6>\n<ul>\n  <li>\nAdjusted LDAP synchronization settings to improve operation on medium and large installations.  </li>\n</ul>\n<h6>\nLibraries</h6>\n<ul>\n  <li>\nUpdate OpenSSL to version 3.5.8  </li>\n  <li>\nUpdate OpenSSH sshd to version 10.4  </li>\n</ul>\n<h6>\nRestAPI</h6>\n<ul>\n  <li>\nAdded auditing capabilities for REST API requests to improve traceability of API activity.  </li>\n  <li>\nCorrected an incomplete API definition for cryptographic certificate information.  </li>\n</ul>\n<h6>\nRule engine</h6>\n<ul>\n  <li>\nAdded message metadata that records actions performed during mail processing, allowing downstream applications to identify how a message was handled.  </li>\n  <li>\nAdded PostgreSQL integration capabilities for Rule Engine custom commands, enabling controlled database lookups and updates for supported use cases.  </li>\n</ul>\n<h6>\nRefactoring</h6>\n<ul>\n  <li>\nModernized the internal implementation used for certificate revocation checks.  </li>\n</ul>\n<h6>\nSecurity</h6>\n<ul>\n  <li>\n    <p>\n<strong>Affected versions:</strong> ≤15.0.6.1 - <strong>CVE-ID:</strong> Pending - <strong>CVSS Score:</strong> 9.9      <br />\n<strong>Description:</strong> Insufficient authorization controls in a cryptographic management API could allow an authenticated user with limited permissions to perform operations beyond their intended scope, potentially affecting system-wide trust configuration.      <br />\n<strong>Fix Description:</strong> Restrict access to the REST endpoint <code class=\"inline\">/crypto/rootca</code> to MSP tokens.    </p>\n  </li>\n  <li>\n    <p>\n<strong>Affected versions:</strong> ≤15.1.0 - <strong>CVE-ID:</strong> Pending - <strong>CVSS Score:</strong> 7.1      <br />\n<strong>Description:</strong> Insufficient output sanitization in the log viewer could allow specially crafted message data to execute unintended browser-side content when viewed by an administrator.      <br />\n<strong>Fix Description:</strong> Escape all external data to prevent content execution.    </p>\n  </li>\n  <li>\n    <p>\nUpdated internal command execution to use safer command-handling mechanisms.    </p>\n  </li>\n</ul>\n<h6>\nWebmail</h6>\n<ul>\n  <li>\nCorrected the styling of generated email notifications to ensure a consistent appearance.  </li>\n  <li>\nAdded support for restricting file types that external communication partners can upload through GINA.  </li>\n</ul>\n"}],"inserted_at":"2026-09-29T07:23:23","updated_at":"2026-09-29T14:49:04","timezone":null,"service_ids":[27401,27403],"featured_from":"2026-09-29T07:18:11","featured_until":null},{"id":248361,"title":"SEPPmail Cloud CH instance: additional IP ranges","url":"https://seppmail.statuspal.eu/info_notices/248361","updates":[{"id":526789,"type":"info","description":"The extension setup of SEPPmail Cloud CH instance is about to go live. With new high performance servers we are ready for future growth. In mid September traffic will start with a few selected NFR partner domains, before gradually going into production with all customers once the new IP addresses have warmed up sufficiently.\r\n\r\nThe oncoming changes should have no influence on customer experience. However, we advise to perform a few checks to ensure mail flow is not affected by configurations tightened to only the current IP addresses of SEPPmail Cloud.\r\nFor all M365 customers: check that certificate based connectors are used to receive mail (this is the case if you used the Powershell-module to create the configuration).\r\nFor all other mailhostings: no firewall rules should block mail traffic to and from our IP ranges. Please ensure traffic to and from 86.119.112.0/28 and 2001:620:6:e0b0::/64 are permitted.\r\nInline outbound customers: ensure SPF include _spf.ch.seppmail.cloud is used.\r\n\r\nManual intervention on customer side should only be required if:\r\nSPF record was built manually instead of using our include. In such case please add the new IP ranges.\r\nIP based connectors or firewall restrictions. In such case either allow all our IP ranges to connect to Port 25.\r\n\r\nInline customer's outgoing mail will be sent via 86.119.87.123 and 2001:620:6:e0b0::58 instead of 86.119.38.33 and 2001:620:5ca1:1f0:f816:3eff:fef0:1d65\r\nParallel customer's incoming and outgoing mail will be sent via 86.119.88.140 instead of 86.119.37.4.\r\nNo manual intervention on customer side should be necessary unless some firewall restrictions would prevent access to port 25 of those IP addresses. \r\n\r\nInline customers MX records IP addresses will be updated to 86.119.88.191 and 2001:620:6:e0b0::35 from 86.119.35.35 and 2001:620:5ca1:1f0:f816:3eff:fe96:d78e. No action of any kind should be required on customer side.\r\n\r\nAll previous IP addresses and ranges remain active for the moment. Customers of DE instance are not affected in any way. Our IP addresses are published in https://docs.seppmail.com/ch/cloud/c07_cloud_onboarding_appendix_ip_addresses.html","inserted_at":"2026-09-09T08:46:03","updated_at":"2026-09-09T08:46:03","posted_at":"2026-09-09T08:31:31","subscribers_notified_at":"2026-09-09T08:46:03","description_html":"<p>\nThe extension setup of SEPPmail Cloud CH instance is about to go live. With new high performance servers we are ready for future growth. In mid September traffic will start with a few selected NFR partner domains, before gradually going into production with all customers once the new IP addresses have warmed up sufficiently.</p>\n<p>\nThe oncoming changes should have no influence on customer experience. However, we advise to perform a few checks to ensure mail flow is not affected by configurations tightened to only the current IP addresses of SEPPmail Cloud.  <br />\nFor all M365 customers: check that certificate based connectors are used to receive mail (this is the case if you used the Powershell-module to create the configuration).  <br />\nFor all other mailhostings: no firewall rules should block mail traffic to and from our IP ranges. Please ensure traffic to and from 86.119.112.0/28 and 2001:620:6:e0b0::/64 are permitted.  <br />\nInline outbound customers: ensure SPF include _spf.ch.seppmail.cloud is used.</p>\n<p>\nManual intervention on customer side should only be required if:  <br />\nSPF record was built manually instead of using our include. In such case please add the new IP ranges.  <br />\nIP based connectors or firewall restrictions. In such case either allow all our IP ranges to connect to Port 25.</p>\n<p>\nInline customer’s outgoing mail will be sent via 86.119.87.123 and 2001:620:6:e0b0::58 instead of 86.119.38.33 and 2001:620:5ca1:1f0:f816:3eff:fef0:1d65  <br />\nParallel customer’s incoming and outgoing mail will be sent via 86.119.88.140 instead of 86.119.37.4.  <br />\nNo manual intervention on customer side should be necessary unless some firewall restrictions would prevent access to port 25 of those IP addresses. </p>\n<p>\nInline customers MX records IP addresses will be updated to 86.119.88.191 and 2001:620:6:e0b0::35 from 86.119.35.35 and 2001:620:5ca1:1f0:f816:3eff:fe96:d78e. No action of any kind should be required on customer side.</p>\n<p>\nAll previous IP addresses and ranges remain active for the moment. Customers of DE instance are not affected in any way. Our IP addresses are published in <a target=\"_blank\" href=\"https://docs.seppmail.com/ch/cloud/c07_cloud_onboarding_appendix_ip_addresses.html\">https://docs.seppmail.com/ch/cloud/c07_cloud_onboarding_appendix_ip_addresses.html</a></p>\n"}],"inserted_at":"2026-09-09T08:46:03","updated_at":"2026-10-01T13:31:28","timezone":null,"service_ids":[5631,5481],"featured_from":"2026-09-09T08:31:31","featured_until":"2026-12-31T11:00:00"},{"id":247938,"title":"New Appliance Release 15.0.7","url":"https://seppmail.statuspal.eu/info_notices/247938","updates":[{"id":525938,"type":"info","description":"A new SEPPmail Appliance release has been published. Please see the [revision history](https://docs.seppmail.com/ch/20_revision-history.html) and the [extended release notes](https://downloads.seppmail.com/extrelnotes/150/ERN15.0.html) for further details.\r\n\r\nOne important point worth mentioning is that Microsoft has switched to the new DigiCert Global Root G2 Certificate Authority. It is therefore highly recommended that you import this certificate into SEPPmail and mark it as trusted to avoid communication issues with Exchange Online.\r\nMore information can be found [here](https://techcommunity.microsoft.com/blog/exchange/trust-digicert-global-root-g2-certificate-authority-to-avoid-exchange-online-ema/4488311). \r\n\r\n### Admin\r\n\r\n* **64063 - Error while deleting a user**\r\n  Fixed an issue that could prevent a local user from being deleted when associated certificate revocation was processed.\r\n  \r\n* **63328 - Error while setting time zone**\r\n  Fixed an issue that prevented time zone settings from being changed or saved correctly.\r\n\r\n### Background tasks\r\n\r\n* **Log old running refresh_maillog_cache.pl processes**\r\n  Improved handling and logging of previously running background processes. This prevents overlapping processes from contributing to excessive resource consumption and system instability.\r\n\r\n### Cfgserver\r\n\r\n* **63328 - Error while setting time zone**\r\n  Fixed an issue that prevented time zone settings from being changed or saved correctly.\r\n\r\n### Clustering\r\n\r\n* **LFM sync not possible because of missing injection connections**\r\n Fixed an issue in the connector.pl service which failed to stop first run injection connections.\r\n\r\n### Operating system\r\n\r\n* **63155 - Cluster view shows SSH warning for cluster member status**\r\n  Updated SSH-related configuration and warning handling to avoid unnecessary warnings when displaying cluster member status.\r\n\r\n### RestAPI\r\n\r\n* **Fix /mailprocessing/ruleset/generate OpenAPI Documentation**\r\n  Corrected the API documentation so requests generated according to the specification are accepted as expected.\r\n\r\n### Rule engine\r\n\r\n* **RuleEngine temp directory is not volatile**\r\n  Corrected temporary directory handling to ensure required processing data remains available while the Rule Engine instance is in use.\r\n\r\n* **63349 - make_lft() drops old output directory which leads to an empty LFT mail**\r\n  Fixed an issue where generated LFT messages could be missing encrypted attachments due to incorrect output directory handling.\r\n\r\n* **63491 - Add specific log output if revocation check is skipped because the next update time for the used CRL is not reached**\r\n  Improved logging to provide a clearer explanation when a revocation check is intentionally skipped.\r\n\r\n### Security\r\n\r\n* **OS command injection in privileged configuration handling**\r\n  **Affected versions:** <15.0.7 - **CVE-ID:** [CVE-2026-84830](https://www.cve.org/CVERecord?id=CVE-2026-84830) - **CVSS Score:** 8.6\r\n  **Description:** SEPPmail Secure Email Gateway before 15.0.7 contains a command injection vulnerability that allows authenticated administrators to execute commands with elevated privileges.\r\n  **Fix Description:** All affected values will be escaped not.\r\n\r\n* **Bypassing mandatory multi-factor authentication (MFA)**\r\n  **Affected versions:** <15.0.7 - **CVE-ID:** [CVE-2026-84831](https://www.cve.org/CVERecord?id=CVE-2026-84831) - **CVSS Score:** 7.7\r\n  **Description:** Under certain conditions, the authentication process could allow a user to gain access before all required multi-factor authentication steps had been completed.\r\n  **Fix Description:** The authentication flow was tightened to ensure all required MFA checks are completed before access is granted.\r\n\r\n* **Unsecure deserialisation in customer import REST endpoint with possible command execution**\r\n  **Affected versions:** <15.0.6 - **CVE-ID:** [CVE-2026-84832](https://www.cve.org/CVERecord?id=CVE-2026-84832) - **CVSS Score:** 8.6\r\n  **Description:** A vulnerability in the processing of specially crafted input could potentially lead to unintended command execution in the affected component.\r\n  **Fix Description:** Additional validation and safer command-handling mechanisms were introduced to prevent malicious input from being executed.\r\n\r\n### Webmail\r\n\r\n* **Processing of hashdecrypt result used wrong secret**\r\n  Corrected an issue where cached webmail data could be validated using an incorrect value, potentially preventing it from being processed correctly.\r\n\r\n* **Fix Session->set() usage**\r\n  Corrected session handling where certain values were not applied as expected, which could cause a session to remain in an incorrect state.\r\n\r\n\r\n","inserted_at":"2026-09-03T21:07:40","updated_at":"2026-09-03T21:07:40","posted_at":"2026-09-03T20:48:44","subscribers_notified_at":"2026-09-03T21:07:40","description_html":"<p>\nA new SEPPmail Appliance release has been published. Please see the <a target=\"_blank\" href=\"https://docs.seppmail.com/ch/20_revision-history.html\">revision history</a> and the <a target=\"_blank\" href=\"https://downloads.seppmail.com/extrelnotes/150/ERN15.0.html\">extended release notes</a> for further details.</p>\n<p>\nOne important point worth mentioning is that Microsoft has switched to the new DigiCert Global Root G2 Certificate Authority. It is therefore highly recommended that you import this certificate into SEPPmail and mark it as trusted to avoid communication issues with Exchange Online.  <br />\nMore information can be found <a target=\"_blank\" href=\"https://techcommunity.microsoft.com/blog/exchange/trust-digicert-global-root-g2-certificate-authority-to-avoid-exchange-online-ema/4488311\">here</a>. </p>\n<h3>\nAdmin</h3>\n<ul>\n  <li>\n    <p>\n<strong>64063 - Error while deleting a user</strong>      <br />\nFixed an issue that could prevent a local user from being deleted when associated certificate revocation was processed.    </p>\n  </li>\n  <li>\n    <p>\n<strong>63328 - Error while setting time zone</strong>      <br />\nFixed an issue that prevented time zone settings from being changed or saved correctly.    </p>\n  </li>\n</ul>\n<h3>\nBackground tasks</h3>\n<ul>\n  <li>\n<strong>Log old running refresh_maillog_cache.pl processes</strong>    <br />\nImproved handling and logging of previously running background processes. This prevents overlapping processes from contributing to excessive resource consumption and system instability.  </li>\n</ul>\n<h3>\nCfgserver</h3>\n<ul>\n  <li>\n<strong>63328 - Error while setting time zone</strong>    <br />\nFixed an issue that prevented time zone settings from being changed or saved correctly.  </li>\n</ul>\n<h3>\nClustering</h3>\n<ul>\n  <li>\n<strong>LFM sync not possible because of missing injection connections</strong>    <br />\nFixed an issue in the connector.pl service which failed to stop first run injection connections.  </li>\n</ul>\n<h3>\nOperating system</h3>\n<ul>\n  <li>\n<strong>63155 - Cluster view shows SSH warning for cluster member status</strong>    <br />\nUpdated SSH-related configuration and warning handling to avoid unnecessary warnings when displaying cluster member status.  </li>\n</ul>\n<h3>\nRestAPI</h3>\n<ul>\n  <li>\n<strong>Fix /mailprocessing/ruleset/generate OpenAPI Documentation</strong>    <br />\nCorrected the API documentation so requests generated according to the specification are accepted as expected.  </li>\n</ul>\n<h3>\nRule engine</h3>\n<ul>\n  <li>\n    <p>\n<strong>RuleEngine temp directory is not volatile</strong>      <br />\nCorrected temporary directory handling to ensure required processing data remains available while the Rule Engine instance is in use.    </p>\n  </li>\n  <li>\n    <p>\n<strong>63349 - make_lft() drops old output directory which leads to an empty LFT mail</strong>      <br />\nFixed an issue where generated LFT messages could be missing encrypted attachments due to incorrect output directory handling.    </p>\n  </li>\n  <li>\n    <p>\n<strong>63491 - Add specific log output if revocation check is skipped because the next update time for the used CRL is not reached</strong>      <br />\nImproved logging to provide a clearer explanation when a revocation check is intentionally skipped.    </p>\n  </li>\n</ul>\n<h3>\nSecurity</h3>\n<ul>\n  <li>\n    <p>\n<strong>OS command injection in privileged configuration handling</strong>      <br />\n<strong>Affected versions:</strong> &lt;15.0.7 - <strong>CVE-ID:</strong> <a target=\"_blank\" href=\"https://www.cve.org/CVERecord?id=CVE-2026-84830\">CVE-2026-84830</a> - <strong>CVSS Score:</strong> 8.6      <br />\n<strong>Description:</strong> SEPPmail Secure Email Gateway before 15.0.7 contains a command injection vulnerability that allows authenticated administrators to execute commands with elevated privileges.      <br />\n<strong>Fix Description:</strong> All affected values will be escaped not.    </p>\n  </li>\n  <li>\n    <p>\n<strong>Bypassing mandatory multi-factor authentication (MFA)</strong>      <br />\n<strong>Affected versions:</strong> &lt;15.0.7 - <strong>CVE-ID:</strong> <a target=\"_blank\" href=\"https://www.cve.org/CVERecord?id=CVE-2026-84831\">CVE-2026-84831</a> - <strong>CVSS Score:</strong> 7.7      <br />\n<strong>Description:</strong> Under certain conditions, the authentication process could allow a user to gain access before all required multi-factor authentication steps had been completed.      <br />\n<strong>Fix Description:</strong> The authentication flow was tightened to ensure all required MFA checks are completed before access is granted.    </p>\n  </li>\n  <li>\n    <p>\n<strong>Unsecure deserialisation in customer import REST endpoint with possible command execution</strong>      <br />\n<strong>Affected versions:</strong> &lt;15.0.6 - <strong>CVE-ID:</strong> <a target=\"_blank\" href=\"https://www.cve.org/CVERecord?id=CVE-2026-84832\">CVE-2026-84832</a> - <strong>CVSS Score:</strong> 8.6      <br />\n<strong>Description:</strong> A vulnerability in the processing of specially crafted input could potentially lead to unintended command execution in the affected component.      <br />\n<strong>Fix Description:</strong> Additional validation and safer command-handling mechanisms were introduced to prevent malicious input from being executed.    </p>\n  </li>\n</ul>\n<h3>\nWebmail</h3>\n<ul>\n  <li>\n    <p>\n<strong>Processing of hashdecrypt result used wrong secret</strong>      <br />\nCorrected an issue where cached webmail data could be validated using an incorrect value, potentially preventing it from being processed correctly.    </p>\n  </li>\n  <li>\n    <p>\n<strong>Fix Session-&gt;set() usage</strong>      <br />\nCorrected session handling where certain values were not applied as expected, which could cause a session to remain in an incorrect state.    </p>\n  </li>\n</ul>\n"}],"inserted_at":"2026-09-03T21:07:40","updated_at":"2026-09-03T21:07:40","timezone":null,"service_ids":[27401,27403],"featured_from":"2026-09-03T20:48:44","featured_until":null},{"id":243416,"title":"New Hotfix Appliance Release 15.0.6.1","url":"https://seppmail.statuspal.eu/info_notices/243416","updates":[{"id":515746,"type":"info","description":"A new SEPPmail Appliance hotfix release has been published.\r\n\r\n**RuleEngine:**\r\n* fixed an issue where an undefined value prevented the message object from writing log entries to the mail log\r\n* added direction detection for archived emails to ensure correct delivery handling\r\n\r\nPlease see the [revision history](https://docs.seppmail.com/ch/20_revision-history.html) and the [extended release notes](https://downloads.seppmail.com/extrelnotes/150/ERN15.0.html) for further details.\r\n","inserted_at":"2026-07-22T15:16:55","updated_at":"2026-07-22T15:16:55","posted_at":"2026-07-22T15:15:10","subscribers_notified_at":"2026-07-22T15:16:55","description_html":"<p>\nA new SEPPmail Appliance hotfix release has been published.</p>\n<p>\n<strong>RuleEngine:</strong></p>\n<ul>\n  <li>\nfixed an issue where an undefined value prevented the message object from writing log entries to the mail log  </li>\n  <li>\nadded direction detection for archived emails to ensure correct delivery handling  </li>\n</ul>\n<p>\nPlease see the <a target=\"_blank\" href=\"https://docs.seppmail.com/ch/20_revision-history.html\">revision history</a> and the <a target=\"_blank\" href=\"https://downloads.seppmail.com/extrelnotes/150/ERN15.0.html\">extended release notes</a> for further details.</p>\n"}],"inserted_at":"2026-07-22T15:16:55","updated_at":"2026-07-22T15:16:55","timezone":null,"service_ids":[27401,27403],"featured_from":"2026-07-22T15:15:10","featured_until":null},{"id":243288,"title":"New Appliance Release 15.0.6","url":"https://seppmail.statuspal.eu/info_notices/243288","updates":[{"id":515486,"type":"info","description":"A new SEPPmail Appliance release has been published. Please see the [revision history](https://docs.seppmail.com/ch/20_revision-history.html) and the [extended release notes](https://downloads.seppmail.com/extrelnotes/150/ERN15.0.html) for further details.\r\n","inserted_at":"2026-07-21T20:37:23","updated_at":"2026-07-21T20:37:23","posted_at":"2026-07-21T18:20:12","subscribers_notified_at":"2026-07-21T20:37:23","description_html":"<p>\nA new SEPPmail Appliance release has been published. Please see the <a target=\"_blank\" href=\"https://docs.seppmail.com/ch/20_revision-history.html\">revision history</a> and the <a target=\"_blank\" href=\"https://downloads.seppmail.com/extrelnotes/150/ERN15.0.html\">extended release notes</a> for further details.</p>\n"}],"inserted_at":"2026-07-21T20:37:23","updated_at":"2026-07-21T20:37:23","timezone":null,"service_ids":[27401,27403],"featured_from":"2026-07-21T18:20:12","featured_until":null},{"id":237185,"title":"New Appliance Release 15.0.5","url":"https://seppmail.statuspal.eu/info_notices/237185","updates":[{"id":502446,"type":"info","description":"A new SEPPmail Appliance release has been published. \r\n\r\n**Admin:**\r\n- Fixed an issue where a CSR could not be displayed in the detail view\r\n- Enforce new admin password after initial login\r\n- Check that the private key and the certificate match when importing an SSL certificate that was issued on the basis of a generated CSR\r\n- Disable all DNS local zone input fields if \"Use DHCP settings\" is selected\r\n\r\n**System Services:**\r\n- Fixed an issue in the auto revocation process\r\n- Fixed failing ruleset generation at startup on HIN appliances\r\n\r\n**Clustering:**\r\n- Extend the connector service to support more complex cluster configurations\r\n\r\n**Logging:**\r\n- Fixed an issue in DB-based logging when there are no entries in the database\r\n\r\n**MPKI:**\r\n- Successful access to EJBCA via SCEP\r\n\r\n**OpenPGP:**\r\n- Switch crypto backend for Sequoia GPG to provide support for legacy algorithms\r\n- Fixed an issue whereby a failed PGP decryption was treated as successful\r\n\r\n**RestAPI:**\r\n- Fixed an issue in the `/mailsystem/template` endpoint when adding templates/disclaimers\r\n- Fixed an issue in the `/system/dns/localzones/{domainName}` endpoint with the DELETE operation\r\n- Fixed an issue with setting a customer's `maximumEncryptionLicenses` and `maximumLFTLicenses` settings\r\n- Fixed an issue with an empty response for `Crypto/Keymaterial`\r\n- Fixed an issue when creating a webmail user\r\n- Fixed an issue with a path parameter in PUT and DELETE of endpoint `/mailsystem/manageddomain/{domainName}/group/{groupName}`\r\n\r\n**Security:**\r\n- Fixed a possible path traversal vulnerability in PDF generation, found by Infoguard ([CVE-2026-8811](https://www.cve.org/CVERecord?id=CVE-2026-8811))\r\n  - With the same vulnerability disclosure, Infoguard found some SSH configuration issues for our update server.\r\n- Base64-encode all PGP decrypted content to prevent MIME structure injection\r\n- Refactor the `hashencrypt` function, used by `pwsend` and cache mode, to use AES-256-CBC with PBKDF2 (CVE pending)\r\n  - Since we already had planned the refactoring, this function was also criticised by ETH.\r\n\r\n**Webmail (GINA):**\r\n- Fixed an issue in the webmail password reset process\r\n- Use PBKDF2-512 as password hashing algorithm (CVE pending)\r\n  - The old hashing algorithm was criticised in the ETH findings\r\n\r\nPlease see the [revision history](https://docs.seppmail.com/ch/20_revision-history.html) and the [extended release notes](https://downloads.seppmail.com/extrelnotes/150/ERN15.0.html) for further details.\r\n","inserted_at":"2026-05-30T13:45:18","updated_at":"2026-05-30T13:45:18","posted_at":"2026-05-30T13:33:24","subscribers_notified_at":"2026-05-30T13:45:18","description_html":"<p>\nA new SEPPmail Appliance release has been published. </p>\n<p>\n<strong>Admin:</strong></p>\n<ul>\n  <li>\nFixed an issue where a CSR could not be displayed in the detail view  </li>\n  <li>\nEnforce new admin password after initial login  </li>\n  <li>\nCheck that the private key and the certificate match when importing an SSL certificate that was issued on the basis of a generated CSR  </li>\n  <li>\nDisable all DNS local zone input fields if “Use DHCP settings” is selected  </li>\n</ul>\n<p>\n<strong>System Services:</strong></p>\n<ul>\n  <li>\nFixed an issue in the auto revocation process  </li>\n  <li>\nFixed failing ruleset generation at startup on HIN appliances  </li>\n</ul>\n<p>\n<strong>Clustering:</strong></p>\n<ul>\n  <li>\nExtend the connector service to support more complex cluster configurations  </li>\n</ul>\n<p>\n<strong>Logging:</strong></p>\n<ul>\n  <li>\nFixed an issue in DB-based logging when there are no entries in the database  </li>\n</ul>\n<p>\n<strong>MPKI:</strong></p>\n<ul>\n  <li>\nSuccessful access to EJBCA via SCEP  </li>\n</ul>\n<p>\n<strong>OpenPGP:</strong></p>\n<ul>\n  <li>\nSwitch crypto backend for Sequoia GPG to provide support for legacy algorithms  </li>\n  <li>\nFixed an issue whereby a failed PGP decryption was treated as successful  </li>\n</ul>\n<p>\n<strong>RestAPI:</strong></p>\n<ul>\n  <li>\nFixed an issue in the <code class=\"inline\">/mailsystem/template</code> endpoint when adding templates/disclaimers  </li>\n  <li>\nFixed an issue in the <code class=\"inline\">/system/dns/localzones/{domainName}</code> endpoint with the DELETE operation  </li>\n  <li>\nFixed an issue with setting a customer’s <code class=\"inline\">maximumEncryptionLicenses</code> and <code class=\"inline\">maximumLFTLicenses</code> settings  </li>\n  <li>\nFixed an issue with an empty response for <code class=\"inline\">Crypto/Keymaterial</code>  </li>\n  <li>\nFixed an issue when creating a webmail user  </li>\n  <li>\nFixed an issue with a path parameter in PUT and DELETE of endpoint <code class=\"inline\">/mailsystem/manageddomain/{domainName}/group/{groupName}</code>  </li>\n</ul>\n<p>\n<strong>Security:</strong></p>\n<ul>\n  <li>\nFixed a possible path traversal vulnerability in PDF generation, found by Infoguard (<a target=\"_blank\" href=\"https://www.cve.org/CVERecord?id=CVE-2026-8811\">CVE-2026-8811</a>)    <ul>\n      <li>\nWith the same vulnerability disclosure, Infoguard found some SSH configuration issues for our update server.      </li>\n    </ul>\n  </li>\n  <li>\nBase64-encode all PGP decrypted content to prevent MIME structure injection  </li>\n  <li>\nRefactor the <code class=\"inline\">hashencrypt</code> function, used by <code class=\"inline\">pwsend</code> and cache mode, to use AES-256-CBC with PBKDF2 (CVE pending)    <ul>\n      <li>\nSince we already had planned the refactoring, this function was also criticised by ETH.      </li>\n    </ul>\n  </li>\n</ul>\n<p>\n<strong>Webmail (GINA):</strong></p>\n<ul>\n  <li>\nFixed an issue in the webmail password reset process  </li>\n  <li>\nUse PBKDF2-512 as password hashing algorithm (CVE pending)    <ul>\n      <li>\nThe old hashing algorithm was criticised in the ETH findings      </li>\n    </ul>\n  </li>\n</ul>\n<p>\nPlease see the <a target=\"_blank\" href=\"https://docs.seppmail.com/ch/20_revision-history.html\">revision history</a> and the <a target=\"_blank\" href=\"https://downloads.seppmail.com/extrelnotes/150/ERN15.0.html\">extended release notes</a> for further details.</p>\n"}],"inserted_at":"2026-05-30T13:45:18","updated_at":"2026-05-30T13:45:18","timezone":null,"service_ids":[27401,27403],"featured_from":"2026-05-30T13:33:24","featured_until":null},{"id":236411,"title":"Warning: Inbound/Outbound Mail Routing Issue (PowerShell Cloud Module v2.5.0)","url":"https://seppmail.statuspal.eu/info_notices/236411","updates":[{"id":500656,"type":"info","description":"###### Summary\r\nWe have identified an issue in the recently released PowerShell Cloud Module version 2.5.0. A regular expression (regex) failure in this version causes outbound emails to bypass the designated outbound connector, delivering them directly through Exchange Online (EXO) instead.\r\n###### Impact\r\nIf you have deployed or updated transport rules using version 2.5.0, your outbound mail routing may not be processing as intended and will bypass the seppmail.cloud secure gateway.\r\n###### Immediate Mitigation Steps\r\nIf you have already created or updated transport rules using version 2.5.0, you must correct the exception regex string to restore proper mail flow.\r\n###### PowerShell Fix (Recommended)\r\nConnect to Exchange Online PowerShell and run the following command to update the exception pattern on the rule:\r\n###### PowerShell\r\nSet-TransportRule -Identity '[SEPPmail.cloud] - 200 Route outgoing e-mails to SEPPmail' -ExceptIfFromAddressMatchesPatterns '^$|^<>$'\r\nNote: A permanent fix is being integrated into Release 2.5.1, which will be available shortly. If you have not yet updated to v2.5.0, we highly recommend skipping it and waiting for v2.5.1.","inserted_at":"2026-05-22T16:17:00","updated_at":"2026-05-22T16:17:00","posted_at":"2026-05-22T16:14:53","subscribers_notified_at":"2026-05-22T16:17:00","description_html":"<h6>\nSummary</h6>\n<p>\nWe have identified an issue in the recently released PowerShell Cloud Module version 2.5.0. A regular expression (regex) failure in this version causes outbound emails to bypass the designated outbound connector, delivering them directly through Exchange Online (EXO) instead.</p>\n<h6>\nImpact</h6>\n<p>\nIf you have deployed or updated transport rules using version 2.5.0, your outbound mail routing may not be processing as intended and will bypass the seppmail.cloud secure gateway.</p>\n<h6>\nImmediate Mitigation Steps</h6>\n<p>\nIf you have already created or updated transport rules using version 2.5.0, you must correct the exception regex string to restore proper mail flow.</p>\n<h6>\nPowerShell Fix (Recommended)</h6>\n<p>\nConnect to Exchange Online PowerShell and run the following command to update the exception pattern on the rule:</p>\n<h6>\nPowerShell</h6>\n<p>\nSet-TransportRule -Identity ‘[SEPPmail.cloud] - 200 Route outgoing e-mails to SEPPmail’ -ExceptIfFromAddressMatchesPatterns ‘^$|^&lt;&gt;$’  <br />\nNote: A permanent fix is being integrated into Release 2.5.1, which will be available shortly. If you have not yet updated to v2.5.0, we highly recommend skipping it and waiting for v2.5.1.</p>\n"}],"inserted_at":"2026-05-22T16:17:00","updated_at":"2026-05-22T16:17:00","timezone":null,"service_ids":[5631,5481,5632,5629,7558,7559],"featured_from":"2026-05-22T16:14:53","featured_until":null},{"id":234947,"title":"New Hotfix Appliance Release 15.0.4.3","url":"https://seppmail.statuspal.eu/info_notices/234947","updates":[{"id":497589,"type":"info","description":"A new SEPPmail Appliance hotfix release has been published. \r\n\r\nUnfortunately, we had to release another hotfix release due to PGP encryption and decryption issues.\r\nThe main problem was that many PGP keys are still in use that rely on obsolete algorithms marked as insecure, such as ElGamal or DSS.\r\nThe newly included Sequoia GPG rejects these algorithms by default, which caused encryption and decryption problems.\r\nFor now, we will allow Sequoia to use all algorithms that are supported by the original GPG.\r\nIn upcoming releases, we will add warnings for these algorithms. Later, we will also add configuration settings to enable or disable their use.\r\n\r\n\r\nPlease see the [revision history](https://docs.seppmail.com/ch/20_revision-history.html) and the [extended release notes](https://downloads.seppmail.com/extrelnotes/150/ERN15.0.html) for further details.\r\n","inserted_at":"2026-05-11T18:17:32","updated_at":"2026-05-11T18:17:32","posted_at":"2026-05-11T18:09:46","subscribers_notified_at":"2026-05-11T18:17:32","description_html":"<p>\nA new SEPPmail Appliance hotfix release has been published. </p>\n<p>\nUnfortunately, we had to release another hotfix release due to PGP encryption and decryption issues.  <br />\nThe main problem was that many PGP keys are still in use that rely on obsolete algorithms marked as insecure, such as ElGamal or DSS.  <br />\nThe newly included Sequoia GPG rejects these algorithms by default, which caused encryption and decryption problems.  <br />\nFor now, we will allow Sequoia to use all algorithms that are supported by the original GPG.  <br />\nIn upcoming releases, we will add warnings for these algorithms. Later, we will also add configuration settings to enable or disable their use.</p>\n<p>\nPlease see the <a target=\"_blank\" href=\"https://docs.seppmail.com/ch/20_revision-history.html\">revision history</a> and the <a target=\"_blank\" href=\"https://downloads.seppmail.com/extrelnotes/150/ERN15.0.html\">extended release notes</a> for further details.</p>\n"}],"inserted_at":"2026-05-11T18:17:32","updated_at":"2026-05-11T18:17:32","timezone":null,"service_ids":[27401,27403],"featured_from":"2026-05-11T18:09:46","featured_until":null},{"id":231866,"title":"UPDATE: SwissSign - renewal of S/MIME Silver certificates (On Prem)","url":"https://seppmail.statuspal.eu/info_notices/231866","updates":[{"id":491154,"type":"info","description":"In order to ensure that the automatic renewal of the SwissSign Silver Certificate revocation goes smoothly for the SEPPmail Appliances, we recommend the following setting changes to be in effect as soon as possible (and not later than 22.04.2026 at 15:00 GMT+2):\r\nUnder MPKI Settings, enable the following:\r\n* \"Automatically renew expiring certificates if validity days left less than\"\r\n* \"Automatically create certificates for active users without certificates\" : This will ensure that the Automatic Renewal Job, that takes place nightly, will be able to reissue the revoked SwissSign certificates.\r\n\r\nWe also highly recommend, that the \"Automatically renew expiring certificates if validity days left less than\" Option be set to 281 days. This is so that all of the certificates that are potentially marked for revocation are renewed before the revocation takes place. Therefore, there is no interruption of certificate services.\r\n\r\nThe setting changes mentioned above can safely be reverted starting 23.04.2026.","inserted_at":"2026-04-20T14:04:47","updated_at":"2026-04-20T14:04:47","posted_at":"2026-04-20T13:56:57","subscribers_notified_at":"2026-04-20T14:04:47","description_html":"<p>\nIn order to ensure that the automatic renewal of the SwissSign Silver Certificate revocation goes smoothly for the SEPPmail Appliances, we recommend the following setting changes to be in effect as soon as possible (and not later than 22.04.2026 at 15:00 GMT+2):  <br />\nUnder MPKI Settings, enable the following:</p>\n<ul>\n  <li>\n“Automatically renew expiring certificates if validity days left less than”  </li>\n  <li>\n“Automatically create certificates for active users without certificates” : This will ensure that the Automatic Renewal Job, that takes place nightly, will be able to reissue the revoked SwissSign certificates.  </li>\n</ul>\n<p>\nWe also highly recommend, that the “Automatically renew expiring certificates if validity days left less than” Option be set to 281 days. This is so that all of the certificates that are potentially marked for revocation are renewed before the revocation takes place. Therefore, there is no interruption of certificate services.</p>\n<p>\nThe setting changes mentioned above can safely be reverted starting 23.04.2026.</p>\n"}],"inserted_at":"2026-04-20T14:04:47","updated_at":"2026-04-20T14:04:47","timezone":null,"service_ids":[27401,27402],"featured_from":"2026-04-20T13:56:57","featured_until":null}],"maintenances":[],"upcoming_maintenances":[],"current_status_type":null}