VORANT. Threat Intelligence Sign in Get the full feed

GUARDIANWALL MailSuite RCE flaw exploited

critical vulnerability

A critical stack-based buffer overflow in Canon MJ's GUARDIANWALL MailSuite email security product is being actively exploited to achieve remote code execution.

Canon Marketing Japan's GUARDIANWALL MailSuite, an email security appliance offered both on-premises and as a SaaS service, contains a stack-based buffer overflow vulnerability (CVE-2026-32661) rated CVSS 9.8. An attacker can send a specially crafted request to the product's web service to trigger the overflow and execute arbitrary code, potentially gaining full control of the affected mail security gateway.

The vendor has confirmed that exploitation is already occurring in the wild against the on-premises version (Ver 1.4.00 through Ver 2.4.26). The SaaS version (GUARDIANWALL Mail Security Cloud) was patched during scheduled maintenance on April 30, 2026, and is no longer affected. Organizations running the on-premises deployment are urged to apply the vendor's patch immediately and, until patched, implement the workaround mitigations the vendor has published.

Because this product sits at the perimeter to filter email traffic, successful exploitation could give an attacker a foothold inside an organization's network with the ability to intercept or manipulate email flows, making rapid patching a priority for affected users.

Mentioned in this report

Vulnerabilities CVE-2026-32661

Source reporting: https://www.ipa.go.jp/security/security-alert/2026/20260513-jvn.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free