logo

U.S. CISA adds SmarterTools SmarterMail and React Native Community CLI flaws to its Known Exploited Vulnerabilities catalog

ID: 2b212ab0-cda0-5554-8493-da7bf488dae1

STIX ID: report--2b212ab0-cda0-5554-8493-da7bf488dae1

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-02-06

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

CISA added two critical flaws to its Known Exploited Vulnerabilities catalog — CVE-2025-11953 (React Native Metro command injection, actively exploited to deliver PowerShell loaders and a UPX-packed Rust payload) and CVE-2026-24423 (SmarterMail unauthenticated RCE) — with observed real-world attacks, exploitation details, and vendor fixes; federal agencies are ordered to remediate by February 26, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.