CRITICAL
9.0 CVE-2026-94389 Published 30 Sept 2026
AcyMailing SMTP Newsletter Unauthenticated RCE Vulnerability
Worried this affects your website?
The AcyMailing SMTP Newsletter component is exposed to an unauthenticated remote code execution (RCE) vulnerability.
Affected versions include all releases up to and including 11.0.5.
- Attack type: Unauthenticated RCE
- Affected versions: 11.0.5 and earlier
Reference: CVE-2026-94389 on NVD
← Back to Security News