CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

[NEW] [high] Dovecot: Multiple vulnerabilities

highCVE-2023-51764CVE-2023-51766CVE-2026-27852CVE-2026-33263CVE-2026-33604CVE-2026-33605
An attacker can exploit multiple vulnerabilities in Dovecot to bypass security measures, disclose sensitive information, manipulate data, or cause denial-of-service conditions.

CSIRTS triage

What
Dovecot contains multiple vulnerabilities allowing attackers to bypass security measures, disclose sensitive information, manipulate data, or cause denial-of-service.
Who is affected
All Dovecot mail server deployments running affected versions.
Urgency
High; multiple unpatched vulnerabilities affecting a critical email infrastructure component.
Action
Update Dovecot to the latest version addressing CVE-2023-51764, CVE-2023-51766, and CVE-2026-27852 through CVE-2026-33607.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Dovecot

Get an email when a new Dovecot advisory drops — max one per day, one-click unsubscribe.

Details

Source
CERT-Bund (BSI) Security Advisories (DE · national-cert · site)
Severity
high
Published
2026-08-31
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3076

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2023-51764coverage & exploitation statusNVD · CVE.org
CVE-2023-51766coverage & exploitation statusNVD · CVE.org
CVE-2026-27852coverage & exploitation statusNVD · CVE.org
CVE-2026-33263coverage & exploitation statusNVD · CVE.org
CVE-2026-33604coverage & exploitation statusNVD · CVE.org
CVE-2026-33605coverage & exploitation statusNVD · CVE.org
CVE-2026-33606coverage & exploitation statusNVD · CVE.org
CVE-2026-33607coverage & exploitation statusNVD · CVE.org
CVE-2026-40013coverage & exploitation statusNVD · CVE.org
CVE-2026-40014coverage & exploitation statusNVD · CVE.org
CVE-2026-40015coverage & exploitation statusNVD · CVE.org
CVE-2026-40017coverage & exploitation statusNVD · CVE.org
CVE-2026-40018coverage & exploitation statusNVD · CVE.org
CVE-2026-40019coverage & exploitation statusNVD · CVE.org
CVE-2026-40203coverage & exploitation statusNVD · CVE.org
CVE-2026-40204coverage & exploitation statusNVD · CVE.org
CVE-2026-40205coverage & exploitation statusNVD · CVE.org
CVE-2026-4200coverage & exploitation statusNVD · CVE.org
CVE-2026-42007coverage & exploitation statusNVD · CVE.org
CVE-2026-42008coverage & exploitation statusNVD · CVE.org
CVE-2026-42391coverage & exploitation statusNVD · CVE.org
CVE-2026-42392coverage & exploitation statusNVD · CVE.org
CVE-2026-42393coverage & exploitation statusNVD · CVE.org
CVE-2026-42395coverage & exploitation statusNVD · CVE.org
CVE-2026-52681coverage & exploitation statusNVD · CVE.org
CVE-2026-52687coverage & exploitation statusNVD · CVE.org
CVE-2026-73208coverage & exploitation statusNVD · CVE.org
CVE-2026-73209coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for Dovecot

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from CERT-Bund (BSI) Security Advisories