HomeSecurity6,000 SmarterMail servers exposed to the internet and vulnerable to attacks

6,000 SmarterMail servers exposed to the internet and vulnerable to attacks

A new serious cybersecurity incident is causing concern in the global IT community, as more than 6,000 SmarterMail servers remain exposed online and potentially vulnerable to active attacks via a specific vulnerability. The disclosure was made by the non-profit security organization Shadowserver, which systematically monitors malicious activity and critical vulnerabilities worldwide.

SmarterMail

The vulnerability concerns authentication bypass and is classified as critical, as it could allow unauthorized attackers to gain complete control of vulnerable servers.

How the security flaw was discovered

The issue was first identified by cybersecurity firm watchTowr, which reported the vulnerability to SmarterMail developer SmarterToolson January 8. The company responded by issuing a fix on January 15, but did not immediately assign a CVE identifier, which delayed wider community notification.

See also: SoundCloud: Data breach affects 29.8 million accounts

Later, the vulnerability was officially registered as CVE-2026-23760 and rated as critical. According to the technical description, the vulnerability allows for the seizure of administrator accounts and remote code execution (RCE) on the host computer.

SmarterMail: Massive server exposure worldwide

In its latest update, Shadowserver said it is monitoring over 6,000 SmarterMail servers that are labeled as “potentially vulnerable.” Of these, more than 4,200 are located in North America, while nearly 1,000 are located in Asia, underscoring the geographic scope of the risk.

6,000 SmarterMail servers exposed to the internet and vulnerable to attacks

Meanwhile, Macnica threat researcher Yutaka Sejiyamasaid that his own scans identified over 8,550 active SmarterMail installations that have not yet been patched against the CVE-2026-23760 vulnerability.

Active exploitation and automated attacks

watchTowr revealed that it has a proof-of-concept exploitthat only requires knowledge of the administrator's username to work — significantly lowering the technical hurdle for attackers. On January 21, the company received information that the vulnerability was already being actively exploited.

See also: VS Code: Malicious AI extensions steal developer data

The following day, cybersecurity firm Huntress confirmed the existence of malicious attacks, highlighting evidence of massive and automated exploitation of vulnerable servers, which dramatically increases the risk to organizations and businesses.

CISA intervention and deadline for the US

Due to the severity of the situation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-23760 to its list of actively exploited vulnerabilitiesand ordered all federal agencies to take immediate action and secure their servers by February 16.

CISA warned that such vulnerabilities are a "frequent entry point for malicious cybercriminals" and recommends immediately applying updates, following BOD 22-01 , or even discontinuing use of the product if no workaround is available.

See also: Stanley malware toolkit sends you to phishing site while URL remains the same

6,000 SmarterMail servers exposed to the internet and vulnerable to attacks

What should system administrators do?

Experts recommend:

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

  • Immediate installation of available patches
  • Restricting access to administrative interfaces
  • Monitoring logs for suspicious activity
  • Implementing additional authentication mechanisms

The SmarterMail case is yet another reminder that, in the modern digital age, a delay in updating systems can prove disastrous.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS