Singapore CSA Warns of Critical SmarterMail Flaw Enabling Unauthenticated Remote Code Execution
ID: f97b2154-3008-5a1f-a143-24edbdd9ff52
STIX ID: report--f97b2154-3008-5a1f-a143-24edbdd9ff52
Feed Name: The Cyber Express
Threat Score
**CVE-2025-52691 — SmarterMail arbitrary file upload / unauthenticated RCE:** The Cyber Security Agency of Singapore warns that SmarterMail (Build 9406 and earlier) contains a critical arbitrary file upload flaw (CVSS 10.0) that can enable unauthenticated remote code execution; SmarterTools released Build 9413 (Oct 9, 2025) to remediate the issue and administrators are urged to upgrade immediately, though no active exploitation has been reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
