logo

Attackers Reverse‑Engineer Patch to Exploit SmarterMail Admin Bypass in the Wild

ID: c3b68b69-add0-5ddc-9903-0ccfea37e54d

STIX ID: report--c3b68b69-add0-5ddc-9903-0ccfea37e54d

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-01-22

Date Updated: 2026-04-21

Author: Abinaya

...
...

**SmarterMail WT-2026-0001: Active authentication-bypass exploited in the wild —** A design flaw in the ForceResetPassword API lets unauthenticated actors set IsSysAdmin to true and reset administrator passwords without validating the old password, enabling account takeover; attackers have used the gained admin access to create volume mounts that execute arbitrary OS commands as SYSTEM, achieving full remote code execution, with exploitation observed shortly after a patch was released (upgrade to SmarterMail 9511 recommended).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.