CRITICAL 9.0 CVE-2026-94389 Published 30 Sept 2026

AcyMailing SMTP Newsletter Unauthenticated RCE Vulnerability

Worried this affects your website?

The AcyMailing SMTP Newsletter component is exposed to an unauthenticated remote code execution (RCE) vulnerability.

Affected versions include all releases up to and including 11.0.5.

  • Attack type: Unauthenticated RCE
  • Affected versions: 11.0.5 and earlier

Reference: CVE-2026-94389 on NVD

← Back to Security News