Data protection regulations in general are designed to protect the personal data of individuals and impose obligations on organizations that collect, process, and store such personal data. These obligations apply to both our customers and Mimecast. We take our obligations under these data protection regulations (such as GDPR, CCPA, POPIA and PIPEDA) governing the services we provide seriously.
We are always reviewing our products and services and making enhancements to help support our customers’ data privacy compliance journey. We also commit ourselves to data protection through our Data Processing Addendum which is available to our customers.
Scroll down this page for information cards including:
- Certification and Attestation reports (security packs)
- Data Processing Addendum
- AI Development Pledge
- Processing details
- Technical and Organizational Measures
- Sub-processors
- Accessibility Statement
- Privacy Statement
We're here to help. Contacts us at: certificationqueries@mimecast.com.
Trust Center Updates
Adobe Campaign Classic Vulnerability
Summary: Mimecast is not affected by the Adobe Campaign Classic vulnerability
We are aware of a maximum-severity vulnerability recently disclosed in Adobe Campaign Classic. CVE-2026-48449 is an Incorrect Authorization vulnerability affecting Adobe Campaign Classic. It carries a maximum CVSS score of 10.0. Exploitation allows arbitrary code execution without requiring any user interaction. Mimecast does not use Adobe Campaign Classic anywhere in our environment. We can confirm that Mimecast and our customers are not affected by this vulnerability.
We continue to monitor this threat and will update customers if our position changes.
SonicWall SMA 1000 Vulnerability Chain
Summary: Mimecast does not use SonicWall SMA 1000 appliances anywhere in our environment. We can confirm that Mimecast and our customers are not affected by this vulnerability.
We are aware of the recently disclosed vulnerability chain affecting SonicWall SMA 1000 series appliances. The chain involves two flaws. CVE-2026-15409 carries a CVSS 10.0 score and allows an unauthenticated attacker to establish a WebSocket tunnel to internal services on the appliance. CVE-2026-15410 is a post-authentication code injection flaw with a CVSS score of 7.2. Chained together, these flaws let an attacker move from an unauthenticated request to root control of the appliance.
We continue to monitor this threat and will update customers if our position changes.
Cisco Secure Firewall Management Center (FMC)
Mimecast does not run Cisco Secure Firewall Management Center in any part of our environment. These vulnerabilities do not affect our infrastructure or our services to customers.
No action is required by customers. We will continue to monitor for any related developments and will update this notice if our position changes.
Summary
Cisco has disclosed active exploitation of two vulnerabilities in Secure Firewall Management Center (FMC) software:
- CVE-2026-20316. A static credential flaw. CVSS 5.3. Rated High by Cisco due to chaining risk.
- CVE-2026-20079. A critical authentication bypass. CVSS 10.0. Can allow root access.
Both were flagged in Cisco's 29 July advisory update. CISA has added CVE-2026-20316 to its Known Exploited Vulnerabilities catalogue, with a remediation deadline of 1 August 2026 for federal agencies.
Mimecast's AI Vulnerability Intelligence & Attack Surface Management
Mimecast actively monitors coordinated disclosure programs from leading AI developers, including Anthropic, as well as disclosures from multiple sources across the frontier AI ecosystem.
We maintain a comprehensive Vulnerability and Attack Surface Management program that includes, but is not limited to, threat intelligence, industry-leading detection and assessment tools, a bug bounty and vulnerability disclosure program, and penetration testing and red team exercises — all augmented by AI tooling and best practices, and all integral to our Secure Software & Systems Development Lifecycle (SSDLC) program. Vulnerabilities are ranked by severity and exploitability and managed accordingly.
This is part of our standard operating process and further strengthens — but does not alter — how we handle and report incidents.







