logo

SmarterMail Fixes Critical Unauthenticated RCE Flaw with CVSS 9.3 Score

ID: d9ae0590-dcf4-5c60-a61a-b4bee2a2794e

STIX ID: report--d9ae0590-dcf4-5c60-a61a-b4bee2a2794e

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-01-30

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

SmarterTools released fixes for multiple critical SmarterMail flaws, including CVE-2026-24423 — an unauthenticated remote code execution via the ConnectToHub API (CVSS 9.3) — plus other critical and medium-severity issues; CVE-2026-24423 has been added to CISA's Known Exploited Vulnerabilities catalog and is reported to be used in active ransomware operations, so administrators are urged to apply the provided builds (9511/9518) immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.