logo

CISA warns of SmarterMail RCE flaw used in ransomware attacks

ID: 9e2aeaf0-2bf0-57f7-ac1b-b484a19a9c84

STIX ID: report--9e2aeaf0-2bf0-57f7-ac1b-b484a19a9c84

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-02-06

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

CISA warns that SmarterMail contained a critical unauthenticated RCE vulnerability (CVE-2026-24423) in the ConnectToHub API that ransomware actors have exploited; an additional authentication-bypass allowing admin password resets was also reported. SmarterTools released fixes (build 9511 and subsequent 9526), and CISA added the vulnerability to its Known Exploited Vulnerabilities catalog and required remediation or product discontinuation under BOD 22-01 by February 26, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.