
CISA added CVE-2025-24423 (SmarterMail RCE) to the KEV catalog this week. Federal agencies have until end of February to fix it. Quite a few on-prem mail servers are still exposed.
Post summary
CISA has listed CVE-2025-24423, a SmarterMail remote code execution flaw, in its KEV catalog, indicating active exploitation. Federal agencies have until the end of February to patch the exposed on‑prem mail servers.
