SmarterMail Fixes Critical Unauthenticated RCE Flaw with CVSS 9.3 Score
ID: d9ae0590-dcf4-5c60-a61a-b4bee2a2794e
STIX ID: report--d9ae0590-dcf4-5c60-a61a-b4bee2a2794e
Feed Name: The Hacker News
Threat Score
SmarterTools released fixes for multiple critical SmarterMail flaws, including CVE-2026-24423 — an unauthenticated remote code execution via the ConnectToHub API (CVSS 9.3) — plus other critical and medium-severity issues; CVE-2026-24423 has been added to CISA's Known Exploited Vulnerabilities catalog and is reported to be used in active ransomware operations, so administrators are urged to apply the provided builds (9511/9518) immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
