logo

SmarterTools patches critical SmarterMail flaw allowing code execution

ID: f0066d7c-2527-50af-9b8d-c7c131af9bfb

STIX ID: report--f0066d7c-2527-50af-9b8d-c7c131af9bfb

Feed Name: Security Affairs

Threat Score
82/100

Date Published: 2026-01-30

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

SmarterTools released patches for two critical SmarterMail flaws (CVE-2026-24423 and CVE-2026-23760), both scored 9.3, that allow unauthenticated remote code execution and admin account takeover; researchers published proof-of-concept code, Shadowserver reported over 6,000 likely vulnerable servers exposed online, and CISA added CVE-2026-23760 to its Known Exploited Vulnerabilities catalog, prompting urgent patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.