logo

Singapore CSA Warns of Critical SmarterMail Flaw Enabling Unauthenticated Remote Code Execution

ID: f97b2154-3008-5a1f-a143-24edbdd9ff52

STIX ID: report--f97b2154-3008-5a1f-a143-24edbdd9ff52

Feed Name: The Cyber Express

Threat Score
75/100

Date Published: 2025-12-31

Date Updated: 2026-04-23

Author: Ashish Khaitan

...
...

**CVE-2025-52691 — SmarterMail arbitrary file upload / unauthenticated RCE:** The Cyber Security Agency of Singapore warns that SmarterMail (Build 9406 and earlier) contains a critical arbitrary file upload flaw (CVSS 10.0) that can enable unauthenticated remote code execution; SmarterTools released Build 9413 (Oct 9, 2025) to remediate the issue and administrators are urged to upgrade immediately, though no active exploitation has been reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.