Postfix Patches Multiple DoS Vulnerabilities
ANSSI advisory details Postfix flaws allowing remote denial of service and security policy bypass; patches available.
The French national cybersecurity agency (ANSSI/CERT-FR) issued an advisory covering multiple vulnerabilities in the Postfix mail transfer agent affecting a broad range of version branches, from releases prior to 3.5.28 up through 3.11.x before 3.11.7. The vulnerabilities allow a remote attacker to cause a denial of service and to bypass security policy controls. No indication of active exploitation is provided in the advisory.
The Postfix project released fixed versions (3.5.28, 3.6.21, 3.7.23, 3.8.21, 3.9.15, 3.10.14, and 3.11.7) alongside an official announcement. Organizations running Postfix mail servers should identify affected instances and apply the vendor-supplied patches referenced in the Postfix 3.11.7 security bulletin. As this is a widely deployed open-source MTA, exposure is likely across many sectors that operate self-hosted email infrastructure.
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1141
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free