External risk intelligence

Axway SecureTransport Admin SSTI Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.4)

CVE-2026-9177

Axway SecureTransport is a managed file transfer gateway designed to be internet-facing to facilitate external data exchanges. While this specific vulnerability requires administrative privileges, the product itself is commonly deployed as an edge service exposed to the internet.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability exists in Axway SecureTransport's mail template function, allowing attackers with administrative access to execute arbitrary Java code on the server when an email is sent. This could lead to a full compromise of the affected server.

  • Code can be run on servers via email templates.
  • Admin-level access enables severe server compromise.
  • Confirm if this file transfer product is in use.

Attack Path

How an attacker could exploit the issue

An attacker with administrative access to Axway SecureTransport can exploit a server-side template injection flaw in the mail template feature. This allows them to inject and execute arbitrary Java code when emails are sent, potentially leading to full server compromise.

  • Requires administrative privileges.
  • Triggered by rendering mail templates.
  • Leads to full server compromise.

Live Threat

Current exploitation, exposure, and threat context

A Server-Side Template Injection vulnerability in Axway SecureTransport's mail template functionality could allow an administrator to inject and execute arbitrary Java code expressions on the server. This execution occurs when an email template is rendered, potentially leading to full host compromise.

  • Server-side code execution.
  • Admin privileges to inject code.
  • Full host compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical Server-Side Template Injection vulnerability in Axway SecureTransport requires immediate attention from teams managing the product, likely involving application owners, infrastructure, and security operations. The first practical step is to identify all instances of Axway SecureTransport, confirm their exposure and business criticality, and then ascertain the accountable owner to plan for remediation.

  • Own: Application and infrastructure owners.
  • Verify: System presence and reachability.
  • Action: Plan vendor-coordinated patching.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Axway SecureTransport?

Axway SecureTransport is a managed file transfer gateway. It is designed to facilitate secure data exchanges and is commonly deployed as an edge service that handles files between internal systems and external partners or clients.

What does Server-Side Template Injection mean for CVE-2026-9177?

This flaw, classified as CWE-1336, occurs when an application improperly treats user-provided input as part of a template. In this case, the vulnerability allows an authenticated administrator to inject malicious Java code into email templates. The server then unknowingly executes this code during the email rendering process, resulting in full control over the host.

How is this vulnerability triggered?

The flaw is triggered specifically when the mail template functionality processes or renders a modified template. It requires an attacker to already possess administrative credentials to inject the code. It is not triggered by standard file transfer operations, nor can unauthenticated users initiate the injection through common gateway traffic.

Why is this CVE concerning for my organization?

According to Halo Surface Signal, this software is frequently deployed as an internet-facing gateway. Because it is intended to handle external traffic, any server-side vulnerability in this product carries a higher risk profile. Organizations with these gateways should evaluate their presence and reachability, especially if they are accessible from the internet.

What should I do if I use Axway SecureTransport?

Verify if your deployment is running a version prior to 5.5-20260528. Identify all instances of the software within your environment, confirm the responsible owners, and prioritize scheduling the vendor-supplied update to remediate the vulnerability.

References