CVE-2025-52691Active Exploitation(smartertools / smartermail)

HIGHCVSS 10.0 · CRITICALCISA KEV

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch smartertools smartermail systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.

7.8/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-02-16. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-434

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • smartermail

Threat summary

  • Active exploitation appears in 8 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 17 mentions across 12 observed days

What's happening

  • Active exploitation reported across 8 signals
  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 4 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 16 signals
  • Disclosure: 4 classified signals
  • Peaked 8d ago at 3 mentions (2026-01-31); latest day: 1
  • 17 total mentions across 12 days

Affected systems

Products
smartermail

Deep dive

Activity timeline17 mentions / 12d
01223Mentions · 2026-01-27: 1Mentions · 2026-01-28: 2Mentions · 2026-01-29: 1Mentions · 2026-01-31: 3Mentions · 2026-02-02: 1Mentions · 2026-02-17: 1Mentions · 2026-02-19: 2Mentions · 2026-02-25: 1Mentions · 2026-03-04: 2Mentions · 2026-03-22: 1Mentions · 2026-04-11: 1Mentions · 2026-05-26: 1PoC Mentioned / Linked · 2026-01-28: 1PoC Mentioned / Linked · 2026-01-31: 3Exploit Tool / Code · 2026-01-31: 2Exploit Tool / Code · 2026-02-25: 1Active Exploitation · 2026-01-27: 1Active Exploitation · 2026-01-28: 1Active Exploitation · 2026-01-29: 1Active Exploitation · 2026-01-31: 1Active Exploitation · 2026-02-19: 1Active Exploitation · 2026-02-25: 1Active Exploitation · 2026-04-11: 1Active Exploitation · 2026-05-26: 1Patch / Workaround · 2026-01-29: 1Patch / Workaround · 2026-01-31: 1Patch / Workaround · 2026-03-04: 1Technical Details · 2026-01-28: 2Technical Details · 2026-01-29: 1Technical Details · 2026-01-31: 3Technical Details · 2026-02-02: 1Technical Details · 2026-02-17: 1Technical Details · 2026-02-19: 2Technical Details · 2026-02-25: 1Technical Details · 2026-03-04: 2Technical Details · 2026-03-22: 1Technical Details · 2026-04-11: 1Technical Details · 2026-05-26: 101-2701-2801-2901-3102-0202-1702-1902-2503-0403-2204-1105-26
Signal classification6 categories
Active Exploitation
847.1%
Disclosure
423.5%
Exploit
211.8%
PoC
15.9%
General
15.9%
Patch
15.9%
Referenced assets38 URLs
By indicator
Classification over time
DateTotalLabels
2026-01-271
Active Exploitation1
2026-01-282
Active Exploitation1PoC1
2026-01-291
Active Exploitation1
2026-01-313
Active Exploitation1Exploit2
2026-02-021
Disclosure1
2026-02-171
Disclosure1
2026-02-192
Active Exploitation1Disclosure1
2026-02-251
Active Exploitation1
2026-03-042
General1Patch1
2026-03-221
Disclosure1
2026-04-111
Active Exploitation1
2026-05-261
Active Exploitation1
Full discourse17 posts
  • Dark Web Informer@DarkWebInformer
    PoC

    ❗️CVE-2025-52691: SmarterMail Authentication Bypass and RCE PoC https://darkwebinformer.com/cve-2025-52691-smartermail-authentication-bypass-and-rce-poc/

    Post summary

    The post announces CVE‑2025‑52691, highlights a proof‑of‑concept demonstrating authentication bypass and remote code execution in SmarterMail, but does not provide exploit code, patches, or evidence of active exploitation.

    023073348.3K
    165.7K followersView on X
  • Swissky@pentest_swissky
    Disclosure

    Do Smart People Ever Say They’re Smart? (SmarterTools SmarterMail Pre-Auth RCE CVE-2025-52691) - @watchtowrcyber https://labs.watchtowr.com/do-smart-people-ever-say-theyre-smart-smartertools-smartermail-pre-auth-rce-cve-2025-52691/

    Post summary

    The post announces a newly disclosed pre‑authentication RCE vulnerability (CVE‑2025‑52691) in SmarterTools SmarterMail, but does not provide exploit code, evidence of active exploitation, or mitigation details.

    05020102.0K
    21.0K followersView on X
  • Cloudforce One@Cloudforce_One
    Patch

    Cloudflare has released new WAF rules addressing the following CVEs to enhance customer protection. SmarterMail - Arbitrary File Upload (CVE-2025-52691) SmarterMail - Authentication Bypass (CVE-2026-23760) https://developers.cloudflare.com/changelog/post/2026-03-02-waf-release/

    Post summary

    Cloudflare has issued new WAF rules to mitigate two SmarterMail CVEs, providing enhanced protection for its customers.

    1301021.9K
    3.0K followersView on X
  • Florian Hansemann@CyberWarship
    Disclosure

    ''Do Smart People Ever Say They’re Smart? (SmarterTools SmarterMail Pre-Auth RCE CVE-2025-52691)'' #infosec #pentest #redteam #blueteam https://labs.watchtowr.com/do-smart-people-ever-say-theyre-smart-smartertools-smartermail-pre-auth-rce-cve-2025-52691/

    Post summary

    The text announces a newly disclosed pre‑authentication remote code execution vulnerability (CVE-2025-52691) in SmarterTools SmarterMail, without detailing PoC, exploitation activity, or available patches.

    020852.0K
    87.2K followersView on X
  • Crowdfense@crowdfense
    Disclosure

    The following vulnerabilities have been added to our feed: - CVE-2025-49113: Roundcube PHP Object Deserialization RCE - CVE-2025-52691: SmarterMail Arbitrary File Upload RCE - CVE-2026-23760: SmarterMail Authentication Bypass RCE https://www.crowdfense.com/n-day-feed/

    Post summary

    The feed announces three new CVEs affecting Roundcube and SmarterMail, all exposing remote code execution via object deserialization, file upload, and authentication bypass.

    11055772
    2.9K followersView on X
  • WhiskeyHacker@whiskeyhacker
    Active Exploitation

    Langflow is not the only target in this wave. Same campaign: CVE-2025-68613 (n8n RCE), CVE-2025-54068 (Laravel Livewire), CVE-2025-52691 (SmarterMail), CVE-2025-9316 (RMM session ID). 12,000+ systems scanned. Confirmed data theft from an Egyptian aviation organization.

    Post summary

    The text reports an ongoing campaign exploiting multiple CVEs across various platforms, confirming data theft from an Egyptian aviation organization after scanning over 12,000 systems.

    11000210
    4.2K followersView on X
  • CTIWatch@ctiwatchcloud
    Active Exploitation

    🚨 [CRITICAL] Active exploitation detected: CVE-2025-52691 Exploit in the wild confirmed for CVE-2025-52691 (CVSS 10.0). SmarterTools SmarterMail contains an unrestricted upload of file with dangerous type vul... 🔗 http://ctiwatch.cloud/alerts #ZeroDay #ExploitInWild #CyberSecurity

    Post summary

    CVE‑2025‑52691 is being actively exploited in the wild with an unrestricted file upload vulnerability, confirmed by industry alerts.

    00010344
    5.6K followersView on X
  • FortiGuard Labs@FortiGuardLabs
    Active Exploitation

    🔔 New Outbreak Alert: Our researchers are tracking an unauthenticated remote code execution vulnerability (CVE-2025-52691) that is being actively exploited in SmarterTools' #SmarterMail servers. CVSS: 10.0 (Critical) 🚨 Get full details and mitigation guidance: https://ftnt.net/6019h5l1v

    Post summary

    Researchers report CVE‑2025‑52691 as a critical, unauthenticated RCE that is actively exploited in SmarterMail, yet no patch or PoC details are provided.

    00010442
    40.9K followersView on X
  • VulnTracker@vuln_tracker
    General

    Cloudflare customers automatically protected against critical SmarterMail vulnerabilities. CVE-2025-52691: File upload → full server compromise CVE-2026-23760: Unauthenticated admin password reset This is why managed security services matter - protection without manual intervention. http://vulntracker.io/cves/CVE-2025-52691

    Post summary

    Cloudflare automatically protects customers from two critical SmarterMail CVEs, underscoring the importance of managed security services.

    00000132
    381 followersView on X
  • RST Cloud@rst_cloud
    Active Exploitation

    #threatreport #MediumCompleteness January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office Zero-Day | 24-02-2026 Source: https://www.recordedfuture.com/blog/january-2026-cve-landscape Key details below ↓ 🧑‍💻Actors/Campaigns: Fancy_bear Neusploit 💀Threats: Nuclei_tool, Minidoor, Pixynetloader, Covenant_c2_tool, Grunt, Com_hijacking_technique, Supply_chain_technique, 🎯Victims: Enterprise communication platforms, Enterprise management platforms, Government users, Business users, Wordpress sites, Email systems 🏭Industry: Government 🌐Geo: Russian 🔓CVEs: CVE-2026-23760 \[[Vulners](https://vulners.com/cve/CVE-2026-23760)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - smartertools smartermail (<100.0.9511) CVE-2025-34026 \[[Vulners](https://vulners.com/cve/CVE-2025-34026)] - CVSS V3.1: *7.5*, - Vulners: Exploitation: True Soft: - versa-networks concerto (<12.1.2, 12.2.0) CVE-2009-0556 \[[Vulners](https://vulners.com/cve/CVE-2009-0556)] - CVSS V3.1: *8.8*, - Vulners: Exploitation: True Soft: - microsoft office_powerpoint (2004) - microsoft powerpoint (2000, 2002, 2003) CVE-2025-8110 \[[Vulners](https://vulners.com/cve/CVE-2025-8110)] - CVSS V3.1: *8.8*, - Vulners: Exploitation: True Soft: - gogs (le0.13.3) CVE-2026-24423 \[[Vulners](https://vulners.com/cve/CVE-2026-24423)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - smartertools smartermail (<100.0.9511) CVE-2025-68645 \[[Vulners](https://vulners.com/cve/CVE-2025-68645)] - CVSS V3.1: *8.8*, - Vulners: Exploitation: True Soft: - synacor zimbra_collaboration_suite (<10.0.18, <10.1.13) CVE-2018-14634 \[[Vulners](https://vulners.com/cve/CVE-2018-14634)] - CVSS V3.1: *7.8*, - Vulners: Exploitation: True Soft: - paloaltonetworks pan-os (<7.1.23, <8.0.16, <8.1.7) CVE-2026-21509 \[[Vulners](https://vulners.com/cve/CVE-2026-21509)] - CVSS V3.1: *7.8*, - Vulners: Exploitation: True Soft: - microsoft 365_apps (-) - microsoft office (2016, 2019) - microsoft office_long_term_servicing_channel (2021, 2024) CVE-2025-37164 \[[Vulners](https://vulners.com/cve/CVE-2025-37164)] - CVSS V3.1: *10.0*, - Vulners: Exploitation: True Soft: - hpe oneview (le10.20.00) CVE-2026-1340 \[[Vulners](https://vulners.com/cve/CVE-2026-1340)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - ivanti endpoint_manager_mobile (le12.7.0.0) CVE-2026-1281 \[[Vulners](https://vulners.com/cve/CVE-2026-1281)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - ivanti endpoint_manager_mobile (le12.5.0.0, 12.5.1.0, 12.6.0.0, 12.6.1.0, 12.7.0.0) CVE-2026-20045 \[[Vulners](https://vulners.com/cve/CVE-2026-20045)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - cisco unified_communications_manager (<14su5, le15su3a) - cisco unified_communications_manager_im_and_presence_service (<14su5, le15su3a) - cisco unity_connection (<14su5, le15su3) CVE-2026-20931 \[[Vulners](https://vulners.com/cve/CVE-2026-20931)] - CVSS V3.1: *8.0*, - Vulners: Exploitation: Unknown Soft: - microsoft windows_10_1607 (<10.0.14393.8783) - microsoft windows_10_1809 (<10.0.17763.8276) - microsoft windows_10_21h2 (<10.0.19044.6809) - microsoft windows_10_22h2 (<10.0.19045.6809) ... CVE-2026-20805 \[[Vulners](https://vulners.com/cve/CVE-2026-20805)] - CVSS V3.1: *5.5*, - Vulners: Exploitation: True Soft: - microsoft windows_10_1607 (<10.0.14393.8783) - microsoft windows_10_1809 (<10.0.17763.8276) - microsoft windows_10_21h2 (<10.0.19044.6809) - microsoft windows_10_22h2 (<10.0.19045.6809) ... CVE-2025-52691 \[[Vulners](https://vulners.com/cve/CVE-2025-52691)] - CVSS V3.1: *10.0*, - Vulners: Exploitation: True Soft: - smartertools smartermail (<100.0.9413) CVE-2025-31125 \[[Vulners](https://vulners.com/cve/CVE-2025-31125)] - CVSS V3.1: *7.5*, - Vulners: Exploitation: True Soft: - vitejs vite (<4.5.11, <5.4.16, <6.0.13, <6.1.3, <6.2.4) CVE-2026-24858 \[[Vulners](https://vulners.com/cve/CVE-2026-24858)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - fortinet fortianalyzer (le7.0.15, le7.2.11, <7.4.10, <7.6.6) - fortinet fortimanager (le7.0.15, le7.2.11, <7.4.10, <7.6.6) - fortinet fortiproxy (le7.0.22, le7.2.15, le7.4.12, le7.6.4) - fortinet fortiweb (le7.4.11, le7.6.6, le8.0.3) ... CVE-2025-54313 \[[Vulners](https://vulners.com/cve/CVE-2025-54313)] - CVSS V3.1: *7.5*, - Vulners: Exploitation: True Soft: - prettier eslint-config-prettier (8.10.1, 9.1.1, 10.1.6, 10.1.7) CVE-2025-40551 \[[Vulners](https://vulners.com/cve/CVE-2025-40551)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - solarwinds web_help_desk (<2026.1) CVE-2026-20029 \[[Vulners](https://vulners.com/cve/CVE-2026-20029)] - CVSS V3.1: *4.9*, - Vulners: Exploitation: Unknown CVE-2026-23550 \[[Vulners](https://vulners.com/cve/CVE-2026-23550)] - CVSS V3.1: *10.0*, - Vulners: Exploitation: Unknown CVE-2026-23800 \[[Vulners](https://vulners.com/cve/CVE-2026-23800)] - CVSS V3.1: *10.0*, - Vulners: Exploitation: Unknown CVE-2024-37079 \[[Vulners](https://vulners.com/cve/CVE-2024-37079)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - vmware cloud_foundation (<5.2) CVE-2026-24061 \[[Vulners](https://vulners.com/cve/CVE-2026-24061)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - gnu inetutils (le2.7) 🤖LLM extracted TTPs:` T1005, T1027, T1053.005, T1071.001, T1078, T1090, T1098, T1112, T1114.003, T1133, ... 🧨IOCs: - Path: 2 - Registry: 1 - IP: 6 - Email: 4 - File: 2 💽Software: Microsoft Office, Ivanti, Linux, Zimbra Collaboration Suite, WordPress, Outlook, Ivanti EPMM 🔢Algorithms: xor 📜Programming Languages: php #threatreport: In January 2026, there was a noted 5% increase in critical vulnerabilities, with 23 high-impact issues identified. Among these, the exploitation of a significant Microsoft Office zero-day vulnerability (CVE-2026-21509) by Russian state-sponsored group APT28 highlighted ongoing threats to enterprise technologies. This vulnerability, which relates to the reliance on untrusted inputs in security decisions, enabled APT28 to utilize weaponized Rich Text Format (RTF) files to deliver various malicious implants, including MiniDoor, PixyNetLoader, and Covenant Grunt. The exploitation chain initiated with an RTF file that bypassed Office OLE mitigations. The attackers deployed MiniDoor as an Outlook VBA script for email collection, while PixyNetLoader, which created a mutex for persistence, allowed further attacks. A notable aspect of this operation was the use of geography-based evasion to limit the delivery of the malicious payloads, demonstrating the sophistication of the APT28 attacks. In addition to Microsoft, other vendors such as SmarterTools and Ivanti were significantly affected, with SmarterTools reporting multiple critical vulnerabilities allowing authentication bypass and remote code execution (RCE). Specifically, CVE-2026-23760 identified a privilege escalation flaw in SmarterMail, permitting unauthenticated users to reset passwords, demonstrating serious flaws in expected security protocols. Furthermore, the Modular DS WordPress plugin was found to have multiple vulnerabilities, CVE-2026-23550 and CVE-2026-23800, that allowed attackers to gain administrator access without authentication. These vulnerabilities emphasize the risk of widespread exploitation due to the centralized management of multiple WordPress sites.

    Post summary

    The report highlights active exploitation of Microsoft Office zero‑day CVE‑2026‑21509 by APT28, detailing the RTF-based attack chain and associated tools, while also noting related critical vulnerabilities in SmarterTools and WordPress.

    0000074
    589 followersView on X
  • Komodo Cyber Security@Komodosec
    Disclosure

    #VulnerabilityReport #CSASingapore CVE-2025-52691 (CVSS 10): Critical SmarterMail Flaw Opens Servers to Unauthenticated Attacks https://securityonline.info/cve-2025-52691-cvss-10-critical-smartermail-flaw-opens-servers-to-unauthenticated-attacks/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The tweet announces a new critical vulnerability (CVE-2025-52691) in SmarterMail with a CVSS score of 10 that permits unauthenticated attacks, but it offers no proof‑of‑concept, exploit code, or patch information.

    0000056
    1.5K followersView on X
  • ThreatSynop@ThreatSynop
    Exploit

    🚨 New Metasploit Modules Weaponize Critical FreePBX, Cacti, and SmarterMail Flaws (Unauth RCE + Persistence) Metasploit 6.4.111 added seven modules chaining FreePBX auth bypass (CVE-2025-66039) with SQLi (CVE-2025-61675) or unrestricted upload (CVE-2025-61678) for unauth RCE, plus unauth RCE in Cacti <1.2.29 (CVE-2025-24367) and SmarterMail path traversal/file upload (CVE-2025-52691), alongside new persistence modules (Burp extension + SSH key injection). This matters because exploitation is now “push-button,” making rapid patching/segmentation and exposure validation urgent for internet-facing VoIP, monitoring, and mail servers. 🎯 Target: Global/Enterprise IT #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cyberpress.org/metasploit-modules-target-freepbx-cacti-smartermail/

    Post summary

    The post announces new Metasploit modules that provide push‑button exploitation for several critical CVEs in FreePBX, Cacti, and SmarterMail, highlighting the availability of exploit code but not confirming active wild attacks.

    0000095
    196 followersView on X
  • ThreatSynop@ThreatSynop
    Exploit

    🚨 Metasploit Adds 7 Fresh Exploit Modules Targeting FreePBX, Cacti, and SmarterMail (Unauth RCE Chains) This Metasploit update ships new modules chaining FreePBX auth-bypass (CVE-2025-66039) with SQLi (CVE-2025-61675) or unrestricted upload (CVE-2025-61678) to reach unauth RCE, plus unauth RCE for Cacti <1.2.29 (CVE-2025-24367) and SmarterMail file upload/path traversal (CVE-2025-52691) to drop webshells/cron-based persistence. This matters because defenders can immediately validate exposure and prioritize patching/hardening for widely deployed VoIP, monitoring, and mail systems. 🎯 Target: Global/Enterprise IT #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cybersecuritynews.com/metasploit-exploit-modules/

    Post summary

    Metasploit released new modules for several CVEs, providing functional exploit code that chain authentication bypasses and other vulnerabilities to achieve unauthenticated RCE, enabling defenders to test exposure and prioritize patching.

    0000081
    196 followersView on X
  • Marc-Frédéric Gomez@marcfredericgo
    Active Exploitation

    📡 𝗡𝗲𝘄𝘀𝗹𝗲𝘁𝘁𝗲𝗿 Podcast 𝗥𝗮𝗱𝗶𝗼𝗖𝗦𝗜𝗥𝗧 𝗻°𝟰𝟳 | 𝗦𝗲𝗺𝗮𝗶𝗻𝗲 𝗱𝘂 𝟮𝟰 𝗮𝘂 𝟯𝟬 𝗷𝗮𝗻𝘃𝗶𝗲𝗿 𝟮𝟬𝟮𝟲 Récapitulatif des épisodes 558 à 564 du podcast quotidien RadioCSIRT. 𝗩𝘂𝗹𝗻𝗲́𝗿𝗮𝗯𝗶𝗹𝗶𝘁𝗲́𝘀 𝗰𝗿𝗶𝘁𝗶𝗾𝘂𝗲𝘀 𝗲𝘁 𝗞𝗘𝗩 CVE-2026-21962 (Oracle) : PoC publié 24h après le patch CVE-2024-37079 (VMware vCenter, CVSS 9.8) : exploitation par 3 APT chinois confirmée CVE-2026-24061 (GNU InetUtils telnetd) : 800K serveurs exposés, exploitation active CVE-2026-21509 (Microsoft Office) : zero-day exploité activement CVE-2026-24858 (Fortinet) : contournement authentification SSO FortiCloud 𝗖𝗼𝗿𝗿𝗲𝗰𝘁𝗶𝗳𝘀 𝗱'𝘂𝗿𝗴𝗲𝗻𝗰𝗲 Microsoft KB5078127 : seconde mise à jour hors-bande en une semaine SolarWinds Web Help Desk : 6 vulnérabilités dont 4 critiques (RCE non authentifiée) 6000+ serveurs SmarterMail exposés (CVE-2025-52691, CVE-2026-23760) 𝗠𝗲𝗻𝗮𝗰𝗲𝘀 𝗮𝗰𝘁𝗶𝘃𝗲𝘀 DynoWiper (Sandworm) : attaque secteur énergétique polonais Kimwolf : 2M+ dispositifs IoT infectés, présence dans 25% réseaux corporate UAT-8099 (Chine) : ciblage serveurs Microsoft IIS 𝗜𝗻𝗰𝗶𝗱𝗲𝗻𝘁 𝗢𝗣𝗦𝗘𝗖 Directeur par intérim CISA : exfiltration involontaire documents classifiés via ChatGPT 𝗡𝗲𝘄𝘀𝗹𝗲𝘁𝘁𝗲𝗿 𝗰𝗼𝗺𝗽𝗹𝗲̀𝘁𝗲 𝗱𝗶𝘀𝗽𝗼𝗻𝗶𝗯𝗹𝗲 𝗶𝗰𝗶 : https://radiocsirt.substack.com/p/newsletter-radiocsirt-n47?r=57c3ye #Cybersecurity #ThreatIntelligence #CERT #CSIRT #InfoSec

    Post summary

    The newsletter highlights several critical CVEs with confirmed active exploitation, PoC releases, and patches, emphasizing widespread real‑world attacks and mitigations.

    00000131
    414 followersView on X
  • ThreatSynop@ThreatSynop
    Active Exploitation

    🚨 CISA Adds Exploited Microsoft Office, Linux Kernel, Telnetd, and SmarterMail Flaws to KEV — Feb 16 Patch Deadline CISA added five vulnerabilities (CVE-2026-21509, CVE-2018-14634, CVE-2026-24061, CVE-2025-52691, CVE-2026-23760) to the KEV catalog, requiring U.S. federal agencies to remediate by Feb 16, 2026—raising urgency for everyone because these bugs include actively exploited Office bypass, Linux privesc, telnetd argument injection, and unauth SmarterMail file-upload RCE. 🎯 Target: USA/Federal + Global (Microsoft Office, Linux, SmarterMail operators) #️⃣ Category: #Vulnerability #CyberLaw #BlueTeam 🔗 URL: https://www.scworld.com/brief/cisa-adds-critical-microsoft-office-linux-kernel-and-smartermail-vulnerabilities-to-kev-catalog

    Post summary

    CISA has added five critical vulnerabilities to the KEV catalog, noting that they are actively exploited and mandating remediation by a fixed deadline.

    00000232
    196 followersView on X
  • RagingCISO@CisoRaging77913
    Active Exploitation

    CVE-2025-52691: SmarterMail—CVSS 10.0, the perfect score. Unauth file upload → RCE on your mail server. 6,000+ exposed worldwide. Attackers get your emails AND a network pivot point. Still running unpatched? You're not hosting mail, you're hosting hackers.

    Post summary

    CVE-2025-52691 is a high‑severity, unauthenticated file‑upload flaw in SmarterMail that allows remote code execution, and has been actively exploited against over 6,000 exposed servers, enabling attackers to steal emails and pivot into networks. The vulnerability remains unpatched in many environments.

    0000082
    4 followersView on X
  • ThreatSynop@ThreatSynop
    Active Exploitation

    🚨 CISA Adds Actively Exploited Office, SmarterMail, GNU Inetutils Telnetd, and Linux Kernel Flaws to KEV CISA updated its KEV catalog with multiple in-the-wild exploited flaws spanning Microsoft Office (CVE-2026-21509), GNU Inetutils telnetd (CVE-2026-24061), SmarterMail (CVE-2025-52691 and CVE-2026-23760), and a Linux kernel issue—triggering accelerated patch deadlines and prioritization for federal and enterprise defenders. The key risk is immediate: these bugs are being exploited now, so internet-facing email services and legacy telnet exposure should be treated as urgent containment and remediation items. 🎯 Target: Global/Enterprise & Government (Email servers, Linux systems, Office endpoints) #️⃣ Category: #Vulnerability #CyberIntel #BlueTeam 🔗 URL: https://securityaffairs.com/187375/security/u-s-cisa-adds-microsoft-office-gnu-inetutils-smartertools-smartermail-and-linux-kernel-flaws-to-its-known-exploited-vulnerabilities-catalog.html

    Post summary

    The announcement highlights that several CVEs—Microsoft Office, GNU Inetutils Telnetd, SmarterMail, and a Linux kernel flaw—are currently being exploited in the wild, prompting accelerated patching and defensive measures.

    00000113
    196 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsmartertoolssmartermail---

Explore more