Skip to main content

Safety bulletins

Information message from March 6, 2026

Product: Mailion

Affected versions: Versions 2.3.4 and earlier

Threat Level: 8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N)

Vulnerability IDs: BDU:2025-16225

Fixed versions: Mailion versions 2.3.5 and later

Description: "New Cloud Technologies" announces a fix for a critical vulnerability in Mailion Server related to the MongoDB component. The vulnerability was discovered by the internal security team on December 29, 2025, and was fixed as part of the update cycle. The vulnerability's severity level has been classified as high.

According to internal monitoring, there is currently no evidence of active exploitation of this vulnerability.

Recommendations: "New Cloud Technologies" strongly recommends that users of Mailion Server versions 2.3.3 and below immediately upgrade to version 2.3.5 to address this vulnerability. To check for the patch, ensure the application version is 2.3.5 or higher. Users who cannot upgrade immediately are advised to limit access to MongoDB only from hosts that actually connect to the database to mitigate the risk.

Information message from December 26, 2025

Product: Mailion

Affected versions: Versions 2.3.2 and earlier

Threat Level: 9.4 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H)

Vulnerability IDs: BDU:2025-12553

Fixed versions: Mailion versions 2.3.3 and later

Description: "New Cloud Technologies" announces a fix for a critical vulnerability in Mailion Server related to the Redis component. The vulnerability was discovered by the internal security team on October 10, 2025, and was fixed as part of an emergency update cycle. The vulnerability's severity level has been classified as critical.

According to internal monitoring, there is currently no evidence of active exploitation of this vulnerability.

Recommendations: "New Cloud Technologies" strongly recommends that users of Mailion Server versions 2.3.2 and below immediately upgrade to version 2.3.3 to address this vulnerability. To check for the patch, ensure that the application version is 2.3.3 or higher. Users who cannot upgrade immediately are advised to temporarily disable Lua script execution in the Redis configuration to mitigate the risk.

Information message from August 30, 2025

Product: Squadus

Affected versions: versions 1.3.1 and 1.4

Threat Level: 7.4 (CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:H/SI:H/SA:H)

Vulnerability Identifiers: CVE and BDU registration in progress

Fixed versions: Squadus version 1.6.0 and later

Description: "New Cloud Technologies" announces a fix for a potential vulnerability in the Squadus product that could allow authorized users to gain unauthorized access to other users' files. The vulnerability's severity level has been classified as high.

According to internal monitoring, no evidence of exploitation of this vulnerability has been detected to date.

Recommendations: New Cloud Technologies recommends that users of Squadus versions 1.3.1 and 1.4 upgrade to version 1.6.0 to fix this vulnerability.

To check for the patch, ensure that the application version is 1.6.0 or higher.

Information message from August 29, 2025

Product: Squadus

Affected versions: versions 1.0 through 1.6

Threat Level: 5.3 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N)

Vulnerability Identifiers: CVE and BDU registration in progress

Fixed versions: Squadus version 1.6.0 and higher

Description: "New Cloud Technologies" announces a fix for a potential vulnerability in the Squadus product that could allow authorized users to gain unauthorized access to certain system data. The vulnerability's severity level has been classified as medium.

According to internal monitoring, no evidence of exploitation of this vulnerability has been detected to date.

Recommendations: New Cloud Technologies recommends that users of Squadus versions 1.0 through 1.6 upgrade to version 1.6.0 to fix this vulnerability.

To check for the patch, ensure that the application version is 1.6.0 or higher.