CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100741

CRITICALCVSS 9.8NVD feed

Published 27 September 2026 · tracked since 27 September 2026

Description

Eval injection in the JScript event-script dispatcher in Progressive Robot Ltd's hMailServer, versions 6.0.0 through 6.3.3 on Windows, allows a remote, unauthenticated attacker to run arbitrary JScript inside the hMailServer service process, with the privileges of the service account, via a password

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-100741 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100741

CRITICALCVSS 9.8NVD feed

Published 27 September 2026 · tracked since 27 September 2026

Description

Eval injection in the JScript event-script dispatcher in Progressive Robot Ltd's hMailServer, versions 6.0.0 through 6.3.3 on Windows, allows a remote, unauthenticated attacker to run arbitrary JScript inside the hMailServer service process, with the privileges of the service account, via a password

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]