CVE-2026-24423
SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability
Summary
SmarterTools SmarterMail contains a missing authentication for critical function vulnerability in the ConnectToHub API method. This could allow the attacker to point the SmarterMail instance to a malicious HTTP server which serves the malicious OS command and could lead to command execution.
Affected software
Vendor: SmarterTools · Product: SmarterMail
Weakness types (CWE):
What to do
This vulnerability appears in CISA's Known Exploited Vulnerabilities catalog, meaning it is being exploited in the wild. Prioritize patching affected systems and verify exposure across your estate.
Related vulnerabilities in SmarterTools
| CVE | Name | EPSS | Exploited |
|---|---|---|---|
| CVE-2026-23760 | SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channe | 95.7% | Yes |
| CVE-2025-52691 | SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnera | 85.5% | Yes |
Is your domain exposed?
Run a free, instant security report for any domain — exposure score, email auth, TLS and breach metadata.
Get your free reportAll information is aggregated from public sources for awareness only and does not constitute an accusation or a security assessment. No personal data or credentials are published.