logo

Over 6,000 SmarterMail servers exposed to automated hijacking attacks

ID: 55d57434-c913-5fd1-8f7f-ae37a9cf2473

STIX ID: report--55d57434-c913-5fd1-8f7f-ae37a9cf2473

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2026-01-27

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

**Executive summary:** A critical authentication-bypass flaw (CVE-2026-23760) in SmarterTools SmarterMail allows unauthenticated attackers to reset system administrator passwords and achieve remote code execution; a vendor patch was released but security researchers and Shadowserver report thousands (6,000–8,500+) of internet-exposed, likely vulnerable servers and evidence of mass automated exploitation, and CISA has listed the issue as actively exploited — immediate patching or mitigations are recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.