6000+ Vulnerable SmarterTools SmarterMail Servers Exposed to Actively Exploited RCE Vulnerability
ID: edb40b3d-4f2d-56b1-b1d7-4fb4475573e5
STIX ID: report--edb40b3d-4f2d-56b1-b1d7-4fb4475573e5
Feed Name: cybersecurityNews.com
SmarterMail suffers a critical authentication-bypass vulnerability (CVE-2026-23760) in the /api/v1/auth/force-reset-password endpoint that permits unauthenticated password resets for administrator accounts, enabling account takeover and SYSTEM-level remote code execution; security firms have observed active exploitation since January 17, 2026, across over 6,000 exposed servers, and SmarterTools strongly recommends immediate patching, log review, and investigation for web shells or persistent backdoors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
