HomeUpdatesSmarterMail fixes critical RCE vulnerability

SmarterMail fixes critical RCE vulnerability

SmarterTools has patched two more security vulnerabilities in its SmarterMail email software, including a critical bug that could lead to arbitrary code execution.

SmarterMail

The vulnerability, tracked as CVE-2026-24423, has a CVSS score of 9.3/10.0. According to the vulnerability description on CVE.org, “SmarterTools SmarterMail versions prior to version 9511 contain a remote code execution method ConnectToHub API.”

See also: Ivanti EPMM: Exploiting zero-day vulnerabilities – UPDATE NOW

The attacker could direct SmarterMail to a malicious HTTP server, which provides the malicious OS command to be executed by the vulnerable application.

Researchers Sina Kheirkhah and Piotr Bazydlo from watchTowr, Markus Wulftange from CODE WHITE GmbH, and Cale Black from VulnCheck discovered and reported the vulnerability.

SmarterMail: Vulnerability and fixes

The vulnerability has been addressed in Build 9511, released on January 15, 2026. The same release also fixes another critical vulnerability (CVE-2026-23760, CVSS score: 9.3) that has since been actively exploited by cybercriminals.

See also: SolarWinds: Critical RCE vulnerabilities in Web Help Desk

SmarterMail fixes critical RCE vulnerability

Additionally, SmarterTools has released fixes for a moderate severity security vulnerability (CVE-2026-25067, CVSS score: 6.9) that could allow an attacker to facilitate NTLM relay attacks and unauthorized network authentication. This vulnerability has been described as an “unauthenticated path coercion” case affecting the background-of-the-day preview endpoint.

VulnCheck noted that “the application base64 decodes the input provided by the attacker and uses it as a filesystem path without validation.”

On Windows systems, this allows resolving UNC [Universal Naming Convention] paths, causing the SmarterMail service to initiate outbound SMB authentication attempts to servers controlled by attackers. This can be used for credential coercion, NTLM relay attacks , and unauthorized network authentication.

See also: vm2 Node.js: “sandbox escape” vulnerability allows code execution

SmarterMail fixes critical RCE vulnerability

The vulnerability has been fixed in Build 9518, released on January 22, 2026. With two vulnerabilities in SmarterMail being actively exploited in the past week, it is essential that users update to the latest version as soon as possible.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS