High severity7.5NVD Advisory· Published Apr 6, 2026· Updated Apr 9, 2026
CVE-2026-35389
CVE-2026-35389
Description
Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, S/MIME signature verification did not validate the certificate trust chain (checkChain: false). Any email signed with a self-signed or untrusted certificate was displayed as having a valid signature. This vulnerability is fixed in 1.4.11.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/bulwarkmail/webmail/security/advisories/GHSA-v6w6-338p-p256nvdVendor Advisory
News mentions
1- Why Malwarebytes blocks some Yahoo Mail redirectsMalwarebytes Labs · May 14, 2026