logo

CISA Advisory Highlights Exploited SmarterTools Vulnerability in Recent Ransomware Attacks

ID: 5d45bbbb-bdc2-519d-a5ae-ed3e1d3a6e6f

STIX ID: report--5d45bbbb-bdc2-519d-a5ae-ed3e1d3a6e6f

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-02-06

Date Updated: 2026-04-22

Author: Divya

...
...

CISA added SmarterMail CVE-2026-24423 to its Known Exploited Vulnerabilities list after researchers observed active exploitation by ransomware operators. The flaw is a Missing Authentication for Critical Function in the ConnectToHub API that allows unauthenticated remote attackers to induce the server to connect to attacker-controlled HTTP servers and execute returned OS commands, resulting in full RCE; administrators are urged to apply vendor patches, isolate or restrict API access, and monitor for suspicious outbound connections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.