Critical Updates, Security Alerts, and Bulletins

This page is for announcements of critical security or bug fixes, software patch updates, security alerts, and bulletins. The information is updated when these changes are released.

  • Guidelines for reporting security vulnerabilities.
  • Subscribe to email notifications of Critical Patch Updates, Security Alerts, and Bulletins.

MDaemon Email Server - Critical Update MD090126

Fix for ClamAV in MDaemon AntiVirus
No action is required for customers who are not using and do not intend to use the MDaemon AntiVirus licensed feature.

Updated September 1, 2026

Summary

A path traversal vulnerability in WinRAR (CVE-2025-8088) affects ClamAV implementations on Windows. If unpatched, processing a malicious RAR file allows files to be extracted outside ClamAV’s designated temporary scan directory. ClamAV has addressed this issue by updating its integrated UnRAR library to prevent file extraction outside of the designated temporary scan directory on Windows.

Resolution Options

Download and upgrade to MDaemon 26.0.4 or higher, which includes the updated ClamAV library for MDaemon Antivirus (formerly SecurityPlus).

Manual ClamAV Patch: MDaemon AntiVirus customers who are unable to upgrade to MDaemon 26.0.4 can download the ClamAV Long Term Support (LTS) update (clamav-1.4.6) from https://www.clamav.net/downloads and replace the EXEs and DLLs in the MDaemon\SecurityPlus\ClamAVPlugin\ directory with the latest EXE and DLL files from ClamAV.

Affected Software
All supported versions of MDaemon Email Server, 22.0.0 through 26.0.3. Although no longer supported, versions older than 22.0.0 are also affected. It is highly recommended that all MDaemon Email Server customers running an unsupported version renew their license and update to a supported and applicable version* to receive the latest security and software features.

Previous MDaemon Email Server Critical Updates

MDaemon Email Server - Critical Update MD041525

MDaemon Email Server - Critical Update MD041525

Fix to MDaemon Email Server and MDaemon Webmail Vulnerabilities

Updated April 15, 2025

Summary
A cross-site scripting (XSS) vulnerability was reported and addressed. Reference CVE-2025-3929 for additional information.

Affected Software
All supported versions of MDaemon Email Server, 22.0.0 through 25.0.1. We recommend that administrators download and install the applicable version found below to address the issue. Although no longer supported, versions older than 22.0.0 are also affected. It is highly recommended that all MDaemon Email Server customers running an unsupported version renew their license and update to a supported and applicable version* (from the list below) to receive the latest security and software features.

This update includes all changes that were released in previous Critical Updates. See previous updates for additional details.

32 and 64-bit Installers for Microsoft Windows - for Critical Update MD041525 (and includes all changes that were released in previous Critical Updates)

Select the version download link to see the file type and language options.
Version in use * Critical Update Version (click to download)
MDaemon 25.0.x
MDaemon 24.5.x
MDaemon 24.0.x
MDaemon 23.5.x
MDaemon 23.0.x
MDaemon 22.0.x

MDaemon Email Server - Critical Update MD111424

MDaemon Email Server - Critical Update MD111424

Fix to MDaemon Email Server and MDaemon Webmail Vulnerabilities

Updated November 14, 2024

Summary
A cross-site scripting (XSS) vulnerability was reported and has been addressed. Reference CVE-2024-11182 for additional information.

Affected Software
All supported versions of MDaemon Email Server, 22.0.0 through 24.5.0. We recommend that administrators download and install the applicable previous version. Although no longer supported, versions older than 20.0.0 are also affected. It is highly recommended that all MDaemon Email Server customers running an unsupported version renew their license and upgrade to a supported, applicable version* to receive the latest security and software features. Download a previous version of MDaemon.

 

MDaemon Email Server - Critical Update MD062923

MDaemon Email Server - Critical Update MD062923

Critical Update to MDaemon AntiVirus/AntiSpam Engine (MDaemon AntiVirus/AntiSpam licensed feature)

Updated September 26, 2023

Summary
This update addresses the following critical issue for MDaemon users:

Re-integration of Outbreak Protection (Recurrent Pattern Detection). Cyren's proprietary Outbreak Protection service was previously removed as a result of Cyren's insolvency and exit from the industry. That technology has been acquired by a new provider and is now re-licensed and integrated for use in MDaemon Email Server.

Affected Customers
Customers using the optional MDaemon AntiVirus/AntiSpam licensed feature must upgrade to the latest version of MDaemon Email Server for which they are licensed or using (from the list below) to ensure access to the latest variant of Malware Detection (antivirus engine) and the new Outbreak Protection (antispam). Older variants of these products may stop working without notice. Additionally, it is highly recommended that all MDaemon Email Server customers upgrade to a current eligible version* to receive the latest security and software features.

Affected Software
All supported versions of MDaemon Email Server, 22.0.0 through 23.0.X. We recommend that administrators download and install the applicable previous version. Although no longer supported, versions older than 20.0.0 are also affected. It is highly recommended that all MDaemon Email Server customers running an unsupported version renew their license and upgrade to a supported, applicable version* to receive the latest security and software features. Download a previous version of MDaemon.

* Critical updates are free for all users. Customers must download the software version file for which they are eligible (the paid version in use, whether the license is current or expired). If a different/ineligible version is downloaded, that version will stop working after 30 days. MDaemon Technologies recommends always using the current version to ensure you receive the latest security and software features.
Renew/Upgrade your MDaemon license    |    Supported Products

SecurityGateway for Email - Critical Update SG090126

Fix for ClamAV in SecurityGateway

Updated September 1, 2026

Summary

A path traversal vulnerability in WinRAR (CVE-2025-8088) affects ClamAV implementations on Windows. If unpatched, processing a malicious RAR file allows files to be extracted outside ClamAV’s designated temporary scan directory. ClamAV has addressed this issue by updating its integrated UnRAR library to prevent file extraction outside of the designated temporary scan directory on Windows.

Resolution Options

Download and and upgrade to SecurityGateway 12.5.1 or higher, which includes the updated ClamAV library.

Manual ClamAV Patch: SecurityGateway customers who are unable to upgrade to SecurityGateway 12.5.1 can download the ClamAV Long Term Support (LTS) update (clamav-1.4.6) from https://www.clamav.net/downloads and replace the EXEs and DLLs in the \Program Files\MDaemon Technologies\SecurityGateway\plugins\clamav\ directory with the latest EXE and DLL files from ClamAV.

Affected Software
All supported versions of SecurityGateway, 8.0.0 through 12.5.0. Although no longer supported, versions older than 8.0.0 are also affected. It is highly recommended that all MDaemon Email Server customers running an unsupported version renew their license and update to a supported and applicable version* to receive the latest security and software features.

Version in Use* Critical Update Version (click to download)
Security Gateway 9.0.3 and higher

* Critical updates are free for all users. Customers must download the software version file for which they are eligible (the paid version in use, whether the license is current or expired). If a different/ineligible version is downloaded, that version will stop working after 30 days. MDaemon Technologies recommends always using the current version to ensure you receive the latest security and software features.
Renew/Upgrade your Security Gateway license    |    Supported Products