# Kaspersky Secure Mail Gateway RCE flaw patched

Published: 2026-09-18 · Severity: routine
Canonical: https://vorant.io/reports/21b5d9a9-5153-56d6-910a-ff78166a8d17/kaspersky-secure-mail-gateway-rce-flaw-patched

> CERT-FR advisory warns of a remote code execution vulnerability in Kaspersky Secure Mail Gateway versions prior to 3.1.

CERT-FR has published an advisory regarding a vulnerability in Kaspersky Secure Mail Gateway affecting all versions prior to 3.1. The flaw, tracked as CVE-2023-41056, allows a remote attacker to execute arbitrary code on affected systems. No details on exploitation in the wild are provided in the bulletin, and no proof-of-concept or technical exploitation specifics are disclosed.

Defenders operating Kaspersky Secure Mail Gateway should consult the vendor's security bulletin (Kaspersky advisory 12430#170926, published 17 September 2026) and apply available patches to upgrade to version 3.1 or later. As an email gateway product, this system typically sits at a network perimeter processing untrusted content, making remote code execution vulnerabilities in it a priority for timely patching even absent confirmed in-the-wild exploitation.

## Mentioned in this report

- Vulnerabilities: CVE-2023-41056

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1201

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/21b5d9a9-5153-56d6-910a-ff78166a8d17/kaspersky-secure-mail-gateway-rce-flaw-patched.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
