logo

SMTP Smuggling: New Flaw Lets Attackers Bypass Security and Spoof Emails

ID: f49c0512-d833-59aa-b898-64d9a667ef98

STIX ID: report--f49c0512-d833-59aa-b898-64d9a667ef98

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-01-03

Date Updated: 2026-04-23

Author: [email protected] (The Hacker News)

...
...

A new technique named SMTP smuggling abuses inconsistencies in how SMTP servers handle end-of-data sequences to inject additional SMTP commands and submit forged or multiple messages, enabling widespread email spoofing that can bypass DKIM, DMARC, and SPF protections; major vendors and MTAs (Microsoft, GMX, Cisco, Postfix, Sendmail) are affected to varying degrees, CERT/CC issued an advisory, some vendors have patched while certain default configurations (notably Cisco Secure Email) remain exploitable, and mitigations include vendor patches and configuration changes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.