Critical SmarterMail vulnerability under attack, no CVE yet
ID: 98ad0dec-3d84-5bc4-8948-81b0b25595e0
STIX ID: report--98ad0dec-3d84-5bc4-8948-81b0b25595e0
Feed Name: Security Affairs
A critical authentication bypass in SmarterTools SmarterMail (WT-2026-0001), patched on January 15, 2026 in Build 9511, is under active exploitation with no CVE assigned. By abusing the unauthenticated `ForceResetPassword` API and setting `IsSysAdmin` to true, attackers can reset the admin password without validating `OldPassword`, gain administrative access, and escalate to remote code execution (SYSTEM) via built‑in features like Volume Mounts. WatchTowr Labs disclosed the issue; patched systems now enforce password validation, and urgent upgrading is advised due to active attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
