{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/numail/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-82082"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["NUMail"],"_cs_severities":["critical"],"_cs_tags":["remote-code-execution","vulnerability","web-application"],"_cs_type":"threat","_cs_vendors":["Green-Computing"],"content_html":"\u003cp\u003eNUMail, developed by Green-Computing, is affected by an OS command injection vulnerability identified as CVE-2026-82082. This vulnerability allows an unauthenticated remote attacker to inject and execute arbitrary system-level commands on the underlying server host. Given the critical CVSS v3.1 base score of 9.8, this flaw presents a significant risk for complete system compromise. Defenders should prioritize identifying instances of NUMail within their infrastructure and monitor for unauthorized process execution originating from the web application's service account. There is currently no evidence of public exploit code or active exploitation campaigns, but the simplicity of the injection vector necessitates immediate risk assessment and implementation of network-level controls.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to unauthenticated remote code execution with the privileges of the NUMail application, potentially resulting in full server compromise, unauthorized access to email data, and lateral movement within the network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePerform an asset inventory to identify all instances of NUMail in the environment.\u003c/li\u003e\n\u003cli\u003ePatch all affected NUMail installations as soon as a security update is provided by Green-Computing.\u003c/li\u003e\n\u003cli\u003eImplement strict ingress filtering to limit access to NUMail management interfaces to trusted IP addresses only.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous characters (e.g., ;, |, \u0026amp;, $, `) in request parameters, which are typical indicators of command injection attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-28T07:11:33Z","date_published":"2026-08-28T07:11:33Z","id":"https://feed.craftedsignal.io/briefs/2026-08-numail-rce/","summary":"NUMail contains an unauthenticated OS command injection vulnerability allowing remote attackers to execute arbitrary system-level commands on affected servers.","title":"Unauthenticated OS Command Injection in NUMail","url":"https://feed.craftedsignal.io/briefs/2026-08-numail-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - NUMail","version":"https://jsonfeed.org/version/1.1"}