logo

“Enjoy Your Admin Access”: Critical SmarterMail RCE Exploited in the Wild

ID: b12ec6d6-c7cb-5ee6-a08a-a0f07bcf7e5a

STIX ID: report--b12ec6d6-c7cb-5ee6-a08a-a0f07bcf7e5a

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-01-22

Date Updated: 2026-04-23

Author: Ddos

...
...

SmarterMail WT-2026-0001 is a critical authentication bypass in the force-reset-password API allowing unauthenticated attackers to overwrite administrator credentials; adversaries then leverage the product's Volume Mounts feature to execute arbitrary OS commands and achieve SYSTEM-level RCE. The report includes log evidence of exploitation occurring shortly after a vendor patch, and SmarterTools released Build 9511 to add validation of the old password.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.