JPCERT/CC issued alerts for stack-based buffer overflow vulnerabilities affecting Japanese enterprise mail products, including Canon Marketing Japan's GUARDIANWALL MailSuite and Active! mail. In the GUARDIANWALL case, the flaw is tracked as CVE-2026-32661 and allows unauthenticated remote code execution when an attacker sends a crafted request to the product's web service. The vendor said exploitation has already been confirmed in the on-premises edition, raising the risk for organizations that expose the service internally or externally.
Affected GUARDIANWALL MailSuite versions include 1.4.00 through 2.4.26 for the on-premises product, while the SaaS offering, GUARDIANWALL Mail Security Cloud, was remediated during maintenance on April 30, 2026. JPCERT/CC urged administrators to apply vendor patches, review systems for signs of compromise, preserve relevant logs, and continue monitoring vendor guidance for additional mitigations. The separate JPCERT/CC notice on Active! mail indicates a similar stack-based buffer overflow issue in another widely used mail platform, underscoring ongoing risk around mail infrastructure software.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
JPCERT/CC published advisory JPCERT-AT-2026-0013 warning about CVE-2026-32661 in Canon Marketing Japan's GUARDIANWALL MailSuite. It recommended applying the vendor patch, checking for compromise, preserving logs, and monitoring for further vendor guidance.
The developer confirmed that CVE-2026-32661, a stack-based buffer overflow in GUARDIANWALL MailSuite's web service, had already been exploited in the on-premises version. The flaw affects versions 1.4.00 through 2.4.26 and can enable unauthenticated remote code execution via a crafted request.
Canon Marketing Japan remediated the vulnerability in the SaaS version, GUARDIANWALL Mail Security Cloud, during scheduled maintenance. This fix preceded the public advisory for the on-premises product.
JPCERT/CC published an advisory about a stack-based buffer overflow vulnerability in Active! mail. The reference provides no further details beyond the advisory topic.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.