# GUARDIANWALL MailSuite RCE flaw exploited

Published: 2026-05-12 · Severity: critical
Canonical: https://vorant.io/reports/7b222eca-e84d-559b-a212-be9eb4313dc9/guardianwall-mailsuite-rce-flaw-exploited

> A critical stack-based buffer overflow in Canon MJ's GUARDIANWALL MailSuite email security product is being actively exploited to achieve remote code execution.

Canon Marketing Japan's GUARDIANWALL MailSuite, an email security appliance offered both on-premises and as a SaaS service, contains a stack-based buffer overflow vulnerability (CVE-2026-32661) rated CVSS 9.8. An attacker can send a specially crafted request to the product's web service to trigger the overflow and execute arbitrary code, potentially gaining full control of the affected mail security gateway.

The vendor has confirmed that exploitation is already occurring in the wild against the on-premises version (Ver 1.4.00 through Ver 2.4.26). The SaaS version (GUARDIANWALL Mail Security Cloud) was patched during scheduled maintenance on April 30, 2026, and is no longer affected. Organizations running the on-premises deployment are urged to apply the vendor's patch immediately and, until patched, implement the workaround mitigations the vendor has published.

Because this product sits at the perimeter to filter email traffic, successful exploitation could give an attacker a foothold inside an organization's network with the ability to intercept or manipulate email flows, making rapid patching a priority for affected users.

## Mentioned in this report

- Vulnerabilities: CVE-2026-32661

Source reporting: https://www.ipa.go.jp/security/security-alert/2026/20260513-jvn.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/7b222eca-e84d-559b-a212-be9eb4313dc9/guardianwall-mailsuite-rce-flaw-exploited.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
