Safety bulletins
Information message from March 6, 2026
Product: Mailion
Affected versions: Versions 2.3.4 and earlier
Threat Level: 8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N)
Vulnerability IDs: BDU:2025-16225
Fixed versions: Mailion versions 2.3.5 and later
Description: "New Cloud Technologies" announces a fix for a critical vulnerability in Mailion Server related to the MongoDB component. The vulnerability was discovered by the internal security team on December 29, 2025, and was fixed as part of the update cycle. The vulnerability's severity level has been classified as high.
According to internal monitoring, there is currently no evidence of active exploitation of this vulnerability.
Recommendations: "New Cloud Technologies" strongly recommends that users of Mailion Server versions 2.3.3 and below immediately upgrade to version 2.3.5 to address this vulnerability. To check for the patch, ensure the application version is 2.3.5 or higher. Users who cannot upgrade immediately are advised to limit access to MongoDB only from hosts that actually connect to the database to mitigate the risk.
Information message from December 26, 2025
Product: Mailion
Affected versions: Versions 2.3.2 and earlier
Threat Level: 9.4 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H)
Vulnerability IDs: BDU:2025-12553
Fixed versions: Mailion versions 2.3.3 and later
Description: "New Cloud Technologies" announces a fix for a critical vulnerability in Mailion Server related to the Redis component. The vulnerability was discovered by the internal security team on October 10, 2025, and was fixed as part of an emergency update cycle. The vulnerability's severity level has been classified as critical.
According to internal monitoring, there is currently no evidence of active exploitation of this vulnerability.
Recommendations: "New Cloud Technologies" strongly recommends that users of Mailion Server versions 2.3.2 and below immediately upgrade to version 2.3.3 to address this vulnerability. To check for the patch, ensure that the application version is 2.3.3 or higher. Users who cannot upgrade immediately are advised to temporarily disable Lua script execution in the Redis configuration to mitigate the risk.
Information message from August 30, 2025
Product: Squadus
Affected versions: versions 1.3.1 and 1.4
Threat Level: 7.4 (CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:H/SI:H/SA:H)
Vulnerability Identifiers: CVE and BDU registration in progress
Fixed versions: Squadus version 1.6.0 and later
Description: "New Cloud Technologies" announces a fix for a potential vulnerability in the Squadus product that could allow authorized users to gain unauthorized access to other users' files. The vulnerability's severity level has been classified as high.
According to internal monitoring, no evidence of exploitation of this vulnerability has been detected to date.
Recommendations: New Cloud Technologies recommends that users of Squadus versions 1.3.1 and 1.4 upgrade to version 1.6.0 to fix this vulnerability.
To check for the patch, ensure that the application version is 1.6.0 or higher.
Information message from August 29, 2025
Product: Squadus
Affected versions: versions 1.0 through 1.6
Threat Level: 5.3 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N)
Vulnerability Identifiers: CVE and BDU registration in progress
Fixed versions: Squadus version 1.6.0 and higher
Description: "New Cloud Technologies" announces a fix for a potential vulnerability in the Squadus product that could allow authorized users to gain unauthorized access to certain system data. The vulnerability's severity level has been classified as medium.
According to internal monitoring, no evidence of exploitation of this vulnerability has been detected to date.
Recommendations: New Cloud Technologies recommends that users of Squadus versions 1.0 through 1.6 upgrade to version 1.6.0 to fix this vulnerability.
To check for the patch, ensure that the application version is 1.6.0 or higher.