8000+ SmarterMail Hosts Vulnerable to RCE Attack – PoC Exploit Released
ID: f4bd3f57-e86d-537e-9bbd-ac5c1b1a1abe
STIX ID: report--f4bd3f57-e86d-537e-9bbd-ac5c1b1a1abe
Feed Name: cybersecurityNews.com
A critical unauthenticated file-upload vulnerability (CVE-2025-52691, CVSS 10.0) in SmarterMail Build 9406 and earlier enables remote code execution; scans from January 12, 2026 found roughly 8,001 of 18,783 exposed instances vulnerable (notably concentrated in the US). Public proof-of-concept exploits are available, increasing exploitation risk despite no confirmed widespread in-the-wild attacks; administrators are urged to upgrade to Build 9413 or later (preferably Build 9483), restrict external access, monitor for anomalous uploads and unexpected files, and use tools like Shadowserver to verify exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
