CVE-2026-9177
Axway · SecureTransport
Axway SecureTransport is vulnerable to server-side template injection in its mail template functionality, allowing authenticated admins to execute arbitrary code.
Executive summary
An authenticated server-side template injection vulnerability in Axway SecureTransport allows administrators to execute arbitrary code, leading to full host compromise.
Vulnerability
The mail template engine fails to properly neutralize user-supplied input. An attacker with administrative privileges can inject malicious Java code expressions into email templates, which are then executed by the server during the rendering process.
Business impact
While this vulnerability requires administrative privileges, the outcome of a successful exploit is total host compromise. This presents a severe risk to the confidentiality, integrity, and availability of the SecureTransport environment and any data managed by the system, as reflected by the high CVSS score.
Remediation
Immediate Action: Update Axway SecureTransport to version 5.5-20260528 or the latest available maintenance release.
Proactive Monitoring: Review administrative audit logs for any suspicious modifications to mail templates or unexpected system behavior during email dispatch.
Compensating Controls: Restrict administrative access to the SecureTransport console to a limited set of trusted personnel and implement strict network segmentation for the management interface.
Exploitation status
Public Exploit Available: No (unknown)
Analyst recommendation
Organizations utilizing Axway SecureTransport should apply the provided update as soon as possible to mitigate the risk of remote code execution. Maintaining the principle of least privilege for administrative accounts is essential to preventing exploitation of this vulnerability.