Shadowserver finds 6,000+ likely vulnerable SmarterMail servers exposed online
ID: bd00b0b1-9d52-5b03-89a9-b7b635f337ff
STIX ID: report--bd00b0b1-9d52-5b03-89a9-b7b635f337ff
Feed Name: Security Affairs
Shadowserver and researchers reported a critical authentication bypass in SmarterMail (CVE-2026-23760) affecting versions prior to build 9511 that permits anonymous password resets of administrator accounts, enabling full administrative compromise and potential remote code execution; over 6,000 servers were identified as likely vulnerable, a public proof-of-concept was released, exploitation attempts were observed, and CISA added the vulnerability to its Known Exploited Vulnerabilities catalog.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
