Attackers Reverse‑Engineer Patch to Exploit SmarterMail Admin Bypass in the Wild
ID: c3b68b69-add0-5ddc-9903-0ccfea37e54d
STIX ID: report--c3b68b69-add0-5ddc-9903-0ccfea37e54d
Feed Name: cybersecurityNews.com
**SmarterMail WT-2026-0001: Active authentication-bypass exploited in the wild —** A design flaw in the ForceResetPassword API lets unauthenticated actors set IsSysAdmin to true and reset administrator passwords without validating the old password, enabling account takeover; attackers have used the gained admin access to create volume mounts that execute arbitrary OS commands as SYSTEM, achieving full remote code execution, with exploitation observed shortly after a patch was released (upgrade to SmarterMail 9511 recommended).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
