login
quiescence.eu
Skip to content

CVE-2026-24423

SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability

9.8
CVSS
87.7%
EPSS (exploit prob.)
99.7%
EPSS percentile
Yes
Actively exploited
Yes
Ransomware use
2026-02-05
Added

Summary

SmarterTools SmarterMail contains a missing authentication for critical function vulnerability in the ConnectToHub API method. This could allow the attacker to point the SmarterMail instance to a malicious HTTP server which serves the malicious OS command and could lead to command execution.

Affected software

Vendor: SmarterTools  ·  Product: SmarterMail

Weakness types (CWE):

CWE-306

What to do

This vulnerability appears in CISA's Known Exploited Vulnerabilities catalog, meaning it is being exploited in the wild. Prioritize patching affected systems and verify exposure across your estate.

Related vulnerabilities in SmarterTools

CVENameEPSSExploited
CVE-2026-23760 SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channe 95.7% Yes
CVE-2025-52691 SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnera 85.5% Yes

Is your domain exposed?

Run a free, instant security report for any domain — exposure score, email auth, TLS and breach metadata.

Get your free report

All information is aggregated from public sources for awareness only and does not constitute an accusation or a security assessment. No personal data or credentials are published.