SmarterTools an urgent security advisory for a critical vulnerability in SmarterMail, which could allow attackers to execute remote code on mail servers.
See also: Guide to safe use of email, social media and online banking during the holidays

The vulnerability, which has been documented as CVE-2025-52691, poses a serious threat to organizations using the affected versions of the software.
The vulnerability received a CVSS score of 10.0, the maximum severity rating possible, which highlights the immediate need for remediation by all affected organizations.
CVE-2025-52691 allows unauthenticated attackers to upload arbitrary files to any location on the mail server, without requiring credentials.
This capability paves the way for remote code execution, giving attackers complete control over compromised systems. The fact that the exploit does not require authentication significantly increases the risk, as attackers do not need to bypass security mechanisms to exploit it.
Successful exploitation of the vulnerability could lead to unauthorized access to sensitive email communications, malware installation, data leakage, and potential lateral movement within corporate networks.
See also: How attackers turn SVG files into phishing bait

Organizations using vulnerable versions are at immediate risk of compromise. The issue affects versions of SmarterMail up to and including Build 9406.
Organizations should immediately check the version they are using and prioritize installing security updates. SmarterTools has released Build 9413 to address this critical vulnerability.
Administrators should immediately update all SmarterMail installations, as delaying patch application leaves mail servers exposed to potential attacks.
The vulnerability was discovered by Chua Meng Han of the Centre for Strategic Infocomm Technologies (CSIT).
The Cyber Security Agency (CSA) of Singapore coordinated the responsible disclosure process with SmarterTools Inc., ensuring that a fix was available before public announcement.
See also: Gemini: Deep Research pulls data from Gmail, Drive & Chat

Organizations using SmarterMail should treat the issue as a top priority and apply the security update without any delay.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
