Skip to content
Threat Feed
high advisory

Remote Code Execution Vulnerability in Kaspersky Secure Mail Gateway

A critical remote code execution vulnerability, CVE-2023-41056, in Kaspersky Secure Mail Gateway allows unauthenticated attackers to execute arbitrary code on affected appliances.

CVE search metadata

CVE search record: CVE-2023-41056. Severity: high. CVSS: 8.1. EPSS: 2.58%. KEV: no. Product: Secure Mail Gateway (< 3.1). Brief: Remote Code Execution Vulnerability in Kaspersky Secure Mail Gateway. Brief link: https://feed.craftedsignal.io/briefs/2026-09-kaspersky-smg-rce/

Kaspersky has released a security advisory addressing a remote code execution vulnerability, identified as CVE-2023-41056, within its Secure Mail Gateway product. The vulnerability affects all versions prior to 3.1. This flaw permits an unauthenticated remote attacker to execute arbitrary code on the underlying appliance, potentially leading to a full system compromise. Given that email gateways are internet-facing and process external traffic, this vulnerability represents a high risk for organizations using this software. Defenders should prioritize updating affected appliances to version 3.1 or later as documented in the Kaspersky security bulletin.

Impact

Successful exploitation of this vulnerability allows an unauthenticated attacker to gain remote code execution capabilities on the gateway. This could result in unauthorized access to internal email communications, potential interception of sensitive information, or the use of the appliance as a beachhead to pivot into the internal corporate network.

Recommendation

  • Upgrade all instances of Kaspersky Secure Mail Gateway to version 3.1 or later immediately.
  • Monitor external-facing network perimeters for anomalous traffic patterns directed at the mail gateway appliance, specifically checking for unconventional payloads in SMTP or management traffic.
  • Review the official Kaspersky security bulletin (12430#170926) for additional hardening steps or configuration changes recommended by the vendor.

Immediate actions

Upgrade Kaspersky Secure Mail Gateway to version 3.1 or later.

IT Operations 24h

Mitigations

Patch appliance to version 3.1.

immediate IT Operations

CVE-2023-41056