Postfix patches DoS flaws across 3.x branches
Multiple vulnerabilities in Postfix versions 3.8–3.11 enable remote denial-of-service attacks; patches available for all affected branches.
CERT-FR has issued an advisory for multiple vulnerabilities discovered in the Postfix mail transfer agent affecting all 3.x branches. The flaws allow remote attackers to trigger denial-of-service conditions. The vendor advisory mentions an additional unspecified security issue beyond the DoS vectors.
Affected versions span Postfix 3.8.x prior to 3.8.18, 3.9.x prior to 3.9.12, 3.10.x prior to 3.10.11, and 3.11.x prior to 3.11.4. Patches are available for all affected branches as of the June 17, 2026 security bulletin.
Organisations running Postfix mail infrastructure should prioritise patching to the latest maintenance releases to mitigate the DoS exposure. The scope of the unspecified vulnerability remains unclear from public disclosures.
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0793
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free